SB2016092019 - Arbitrary code execution in Drupal Drupal



SB2016092019 - Arbitrary code execution in Drupal Drupal

Published: September 20, 2016

Security Bulletin ID SB2016092019
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Arbitrary code execution (CVE-ID: N/A)

The vulnerability allows authenticated user to cause arbitary code execution on the target system.
The weakness exists due to validation errors. Attackers can get "post comments" permission and access to more than one input filter that allows them to execute arbitrary code.
Successful exploiatation of the vulnerability leads to arbitrary code execution on the vulnerable system.

Remediation

Install update from vendor's website.