{"id":"DRUPAL-CONTRIB-2018-018","details":"This module helps in exporting and importing Menu Items via the administrative interface.\n\nThe module does not properly restrict access to administrative pages, allowing anonymous users to export and import menu links.\n\nThere is no mitigation for this vulnerability.","modified":"2026-09-10T03:45:58.987472264Z","published":"2018-04-18T15:45:18Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2018-018"}],"affected":[{"package":{"name":"drupal/menu_export","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/menu_export?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.0"}],"database_specific":{"constraint":"\u003c1.2.0"}}],"database_specific":{"affected_versions":"\u003c1.2.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/menu_export/DRUPAL-CONTRIB-2018-018.json"}}],"schema_version":"1.9.0","credits":[{"name":"Nathan Dentzau","contact":["https://www.drupal.org/u/nathandentzau"]}]}