VULNERABILITY INTELLIGENCE
CVE-2008-4792
CVSS score6 MEDIUM
EPSS probability1.28%
CISA KEVNot currently listed
Published2008-10-29
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Description
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
Primary references
- cve@mitre.org — Patch, Vendor Advisory
- cve@mitre.org — Third Party Advisory
- cve@mitre.org — Mailing List, Third Party Advisory
- cve@mitre.org — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry