3.5
CVE-2009-3782
- EPSS 1.04%
- Veröffentlicht 26.10.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
2bits ≫ Userpoints Version6.x-1.0
2bits ≫ Userpoints Version6.x-1.x-dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.04% | 0.594 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://drupal.org/node/610818
http://drupal.org/node/610828
http://osvdb.org/59124
http://secunia.com/advisories/37123
http://www.securityfocus.com/bid/36786
http://www.vupen.com/english/advisories/2009/2998
https://exchange.xforce.ibmcloud.com/vulnerabilities/53896