Vulnerability Bulletins |
SA-CORE-2014-002 - Drupal core - Information Disclosure |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2014-002Project: Drupal coreVersion: 6.x, 7.xDate: 2014-April-16Security risk: Moderately criticalExploitable from: RemoteVulnerability: Information DisclosureDescriptionDrupals form API has built-in support for temporary storage of form state, for example user input. This is often used on multi-step forms, and is required on Ajax-enabled forms in order to allow the Ajax calls to access and update interim user input on the server.When pages are cached for anonymous More info: https://www.drupal.org/SA-CORE-2014-002 |
|






