Executive brief
Drupal Users without "Administer comments" can set comment visibility on nodes they can edit
Affected products
- Packagist drupal/drupal
- Packagist drupal/core
Junglewise Threat Intelligence
CVE-2016-7570 · Severity: low · CVSS 3 · Published 2022-05-17
Technologies: drupal/drupal (Packagist), drupal/core (Packagist). Vendors: Packagist.
Drupal Users without "Administer comments" can set comment visibility on nodes they can edit