 
                        We found results for “”
CVE-2016-9449
Date: November 25, 2016
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
Language: PHP
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
CWE-200CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | NETWORK | 
| Attack Complexity (AC): | LOW | 
| Privileges Required (PR): | LOW | 
| User Interaction (UI): | NONE | 
| Scope (S): | UNCHANGED | 
| Confidentiality (C): | LOW | 
| Integrity (I): | NONE | 
| Availability (A): | NONE | 
CVSS v2
| Base Score: |  | 
|---|---|
| Access Vector (AV): | NETWORK | 
| Access Complexity (AC): | LOW | 
| Authentication (AU): | SINGLE | 
| Confidentiality (C): | PARTIAL | 
| Integrity (I): | NONE | 
| Availability (A): | NONE | 
| Additional information: | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

