Description
Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.
Remediation
References
Related Vulnerabilities
Moodle Incorrect Authorization Vulnerability (CVE-2024-48897)
WordPress Plugin Zingiri Web Shop Cookie Multiple SQL Injection Vulnerabilities (2.4.7)
WordPress Plugin bbPress Like Button SQL Injection (1.5)
WordPress Plugin WooCommerce-Store Exporter CSV Injection (2.3.1)
Moodle Insufficient Verification of Data Authenticity Vulnerability (CVE-2023-5548)