CVE-2016-7572

Publication date

2016-10-03 18:00:00

Family

mitre

State

PUBLISHED

Description

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.