Security Advisory

CVE-2016-7572

4.3
MEDIUM

Vulnerability Description

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.
Published Date October 3, 2016
Official Source NIST NVD Advisory