AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-6924

HIGH · CVSS 7.4 EPSS 2.10%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-15 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.4. See the original NVD description below for full technical details.

CVE
CVE-2017-6924
Severity
HIGH
CVSS
7.4
EPSS
2.10%

Original NVD Description

In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments.

Related CVEs

Other vulnerabilities affecting the same vendor(s)