Vulnerability Bulletins

Drupal Core - Critical - Multiple Vulnerabilities - SA-CORE-2016-004

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2016-004Project: Drupal core Version:li 8.xDate: 2016-September-21Security risk: 18/25 ( Critical) AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:DefaultDescriptionUsers without "Administer comments" can set comment visibility on nodes they can edit. (Less critical) Users who have rights to edit a node, can set the visibility on comments for that node. This should be restricted to those who have the administer comments permission. Cross-site Scripting in http

More info:

https://www.drupal.org/SA-CORE-2016-004