5
CVE-2013-1908
- EPSS 2.56%
- Veröffentlicht 16.07.2013 18:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Commons Wikis Project ≫ Commons Wikis Version <= 7.x-3.0
Commons Wikis Project ≫ Commons Wikis Version7.x-3.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.56% | 0.83 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/52795
https://drupal.org/node/1954948
http://osvdb.org/91747
http://packetstormsecurity.com/files/120995/Drupal-Common-Wikis-7.x-Access-Bypass-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2013/Mar/244
http://secunia.com/advisories/52766
https://drupal.org/node/1954766
https://drupal.org/node/1954768