Beveiligingsadvies
CVE-2016-3169
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.