Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.
We have discovered 134,572 live websites that are affected by CVE-2016-7570.
Product | |
Category | Content Management System |
Vulnerable Domains | 134,572 live websites (53.57% of Drupal install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 30 versions ( 9.84% of all versions) |
![]() | 42,201 websites |
![]() | 13,939 websites |
![]() | 11,930 websites |
![]() | 10,386 websites |
![]() | 4,247 websites |
![]() | 3,940 websites |
![]() | 3,689 websites |
![]() | 3,384 websites |
![]() | 2,839 websites |
![]() | 2,503 websites |
.com | 37,022 websites |
.org | 11,560 websites |
.ru | 9,889 websites |
.de | 7,225 websites |
.fr | 4,923 websites |
.be | 4,360 websites |
.edu | 4,035 websites |
.net | 3,302 websites |
.it | 2,933 websites |
.nl | 2,762 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.org | ![]() | *** | |
***.org | ![]() | *,*** | |
********.gov | ![]() | *,*** | |
******.gov | ![]() | *,*** | |
***.**.gov | ![]() | *,*** | |
******.edu | ![]() | *,*** | |
***.gov | ![]() | *,*** | |
****.org | ![]() | *,*** | |
***.com | ![]() | *,*** | |
*******.com | ![]() | *,*** |
FAQ