4

CVE-2013-1973

The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autocomplete Widgets ProjectAutocomplete Widgets Version6.x-1.0 Update- Edition- SwEdition- SwPlatformdrupal
Autocomplete Widgets ProjectAutocomplete Widgets Version6.x-1.1 Update- Edition- SwEdition- SwPlatformdrupal
Autocomplete Widgets ProjectAutocomplete Widgets Version6.x-1.2 Update- Edition- SwEdition- SwPlatformdrupal
Autocomplete Widgets ProjectAutocomplete Widgets Version6.x-1.3 Update- Edition- SwEdition- SwPlatformdrupal
Autocomplete Widgets ProjectAutocomplete Widgets Version7.x-1.x Updatealpha1 Edition- SwEdition- SwPlatformdrupal
Autocomplete Widgets ProjectAutocomplete Widgets Version7.x-1.x Updatebeta1 Edition- SwEdition- SwPlatformdrupal
Autocomplete Widgets ProjectAutocomplete Widgets Version7.x-1.x Updatebeta2 Edition- SwEdition- SwPlatformdrupal
Autocomplete Widgets ProjectAutocomplete Widgets Version7.x-1.x Updatedev Edition- SwEdition- SwPlatformdrupal
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.478
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N