3.5
CVE-2013-1925
- EPSS 1.77%
- Veröffentlicht 16.07.2013 18:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 Update alpha1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 Update alpha2 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 Update alpha3 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 Update alpha4 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 Update beta1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 Update rc1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.0 Update rc2 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.2 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 7.x-1.x Update dev SwPlatform drupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.77% | 0.753 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
http://osvdb.org/91986
http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.html
http://seclists.org/fulldisclosure/2013/Apr/8
https://drupal.org/node/1960406
https://drupal.org/node/1960424
https://exchange.xforce.ibmcloud.com/vulnerabilities/83254