4.3
CVE-2012-2304
- EPSS 2.1%
- Veröffentlicht 14.08.2012 22:55:02
- Zuletzt bearbeitet 16.06.2026 23:41:19
- Erkennungen
The Linkit module 7.x-2.x before 7.x-2.3 for Drupal, when using an entity access module, does not check permissions when searching for entities, which allows remote attackers to obtain sensitive information via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emil Stjerneman ≫ Linkit Version 7.x-2.0
Emil Stjerneman ≫ Linkit Version 7.x-2.0 Update beta1
Emil Stjerneman ≫ Linkit Version 7.x-2.0 Update beta2
Emil Stjerneman ≫ Linkit Version 7.x-2.1
Emil Stjerneman ≫ Linkit Version 7.x-2.2
Emil Stjerneman ≫ Linkit Version 7.x-2.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.1% | 0.792 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
http://www.openwall.com/lists/oss-security/2012/05/03/1
http://www.openwall.com/lists/oss-security/2012/05/03/2
http://drupal.org/node/1547716
http://drupal.org/node/1547738
http://secunia.com/advisories/48900
http://www.osvdb.org/81557
http://www.securityfocus.com/bid/53253
https://exchange.xforce.ibmcloud.com/vulnerabilities/75183