CVE-2011-2687

high
Published 2011-07-27 · Modified 2024-01-19
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Drupal Access Control Bypass

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/45291

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/45081

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupal.org/node/1204582

Package impact

EcosystemPackageVulnerableFixed
php Packagistdrupal/core>=7.0,<7.37.3

Application impact

VendorProductVersionsFixed
drupaldrupal7.0
drupaldrupal7.1
drupaldrupal7.2

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.