Drupal Core 8.0.x Multiple Vulnerabilities - CVE-2016-3162
Drupal Core is prone to multiple vulnerabilities including security bypass denial of service open redirect and information disclosure vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently view delete or substitute a link to a file to cause the affected website to consume memory and CPU resources by blocking file uploads thus denying service to legitimate users to redirect users to arbitrary web sites and conduct phishing attacks or to obtain sensitive information that may help in launching further attacks. Drupal Core versions 8.0.x ranging from 8.0.0 and up to and including 8.0.3 are vulnerable.
