The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.debian.org/security/2016/dsa-3718 | vendor advisory |
http://www.securityfocus.com/bid/94367 | vdb entry third party advisory |
https://www.drupal.org/SA-CORE-2016-005 | patch vendor advisory |