Description
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2376 | The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition. |
Github GHSA |
GHSA-4gh5-3hqj-x3pj | Drupal Form API ignores access restrictions on submit buttons |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T23:47:57.390Z
Reserved: 2016-03-15T00:00:00.000Z
Link: CVE-2016-3165
No data.
Status : Modified
Published: 2016-04-12T15:59:03.057
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-3165
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA