4.3
CVE-2012-2304
- EPSS 2.1%
- Veröffentlicht 14.08.2012 22:55:02
- Zuletzt bearbeitet 16.06.2026 23:41:19
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Linkit module 7.x-2.x before 7.x-2.3 for Drupal, when using an entity access module, does not check permissions when searching for entities, which allows remote attackers to obtain sensitive information via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emil Stjerneman ≫ Linkit Version7.x-2.0
Emil Stjerneman ≫ Linkit Version7.x-2.0 Updatebeta1
Emil Stjerneman ≫ Linkit Version7.x-2.0 Updatebeta2
Emil Stjerneman ≫ Linkit Version7.x-2.1
Emil Stjerneman ≫ Linkit Version7.x-2.2
Emil Stjerneman ≫ Linkit Version7.x-2.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.1% | 0.792 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
http://www.openwall.com/lists/oss-security/2012/05/03/1
http://www.openwall.com/lists/oss-security/2012/05/03/2
http://drupal.org/node/1547716
http://drupal.org/node/1547738
http://secunia.com/advisories/48900
http://www.osvdb.org/81557
http://www.securityfocus.com/bid/53253
https://exchange.xforce.ibmcloud.com/vulnerabilities/75183