5
CVE-2012-4488
- EPSS 0.27%
- Veröffentlicht 31.10.2012 16:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows remote attackers to read node or user results via the location search page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Location Module Project ≫ Location Version6.x-3.0
Location Module Project ≫ Location Version6.x-3.0 Updaterc1
Location Module Project ≫ Location Version6.x-3.0 Updaterc2
Location Module Project ≫ Location Version6.x-3.0 Updatetest3
Location Module Project ≫ Location Version6.x-3.1
Location Module Project ≫ Location Version6.x-3.1 Updaterc1
Location Module Project ≫ Location Version6.x-3.x Updatedev
Location Module Project ≫ Location Version7.x-1.0 Updatebeta1
Location Module Project ≫ Location Version7.x-3.x Updatedev
Location Module Project ≫ Location Version7.x-4.x Updatedev
Location Module Project ≫ Location Version7.x-5.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.474 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|