Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 7
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Diff_Project Diff
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
|
— |
2.0.1
|
|
Diff_Project Diff
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
|
5.x-1.0
|
<= 5.x-2.1
|
|
Diff_Project Diff
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
|
6.x-1.0
|
<= 6.x-2.3
|
|
Diff_Project Diff
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
|
7.x-3.0
|
<= 7.x-3.5
|
|
Diff_Project Diff
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
|
8.x-1.0
|
<= 8.x-1.10
|
|
Diff_Project Diff
cpe:2.3:a:diff_project:diff:2.1.0:*:*:*:*:drupal:*:*
|
— | — |
|
Diff_Project Diff
cpe:2.3:a:diff_project:diff:4.7.x-1.1:*:*:*:*:drupal:*:*
|
— | — |