CVE-2016-6212: Infoleak
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.
Other sources
Views can allow unauthorized users to see Statistics information
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6212?
CVE-2016-6212 has a medium severity rating, indicating potential unauthorized access to sensitive statistics information.
How do I fix CVE-2016-6212?
To fix CVE-2016-6212, upgrade the Views module to version 7.x-3.14 or 8.x-8.1.3 or later.
Who is affected by CVE-2016-6212?
CVE-2016-6212 affects Drupal versions 7.x before 7.x-3.14 and Drupal 8.x before 8.1.3.
What can attackers do with CVE-2016-6212?
Attackers could potentially bypass access restrictions and access sensitive statistics data.
Is CVE-2016-6212 a remote vulnerability?
Yes, CVE-2016-6212 can be exploited by remote authenticated users.