CVE-2016-6212
published 2016-09-09CVE-2016-6212: The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass…
PriorityP426medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
2.21%
80.4th percentile
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | core | >= 8.0 < 8.1.3 | 8.1.3 |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Drupal Views can allow unauthorized users to see Statistics information
osv·2022-05-17
CVE-2016-6212 [MEDIUM] Drupal Views can allow unauthorized users to see Statistics information
Drupal Views can allow unauthorized users to see Statistics information
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.
GHSA
Drupal Views can allow unauthorized users to see Statistics information
ghsa·2022-05-17
CVE-2016-6212 [MEDIUM] CWE-200 Drupal Views can allow unauthorized users to see Statistics information
Drupal Views can allow unauthorized users to see Statistics information
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2016/07/13/4http://www.openwall.com/lists/oss-security/2016/07/13/7http://www.securityfocus.com/bid/91230https://www.drupal.org/SA-CORE-2016-002https://www.drupal.org/node/2749333http://www.openwall.com/lists/oss-security/2016/07/13/4http://www.openwall.com/lists/oss-security/2016/07/13/7http://www.securityfocus.com/bid/91230https://www.drupal.org/SA-CORE-2016-002https://www.drupal.org/node/2749333
2016-09-09
Published