VULNERABILITY INTELLIGENCE

CVE-2008-4792

CVSS score6 MEDIUM
EPSS probability1.28%
CISA KEVNot currently listed
Published2008-10-29
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:S/C:P/I:P/A:P

Description

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

Primary references