CVE-2016-7570

Publication date

2016-10-03 18:00:00

Family

mitre

State

PUBLISHED

Description

Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.