SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-6160

Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and…

MEDIUM 5.0EPSS 1.90%

Does this matter?

Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.

Description

Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.90% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
drupal/semantically interconnected online communities
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.