5
CVE-2013-2122
- EPSS 1.56%
- Veröffentlicht 16.07.2013 18:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Quade ≫ Edit Limit Version 7.x-1.0
Quade ≫ Edit Limit Version 7.x-1.0 Update beta1
Quade ≫ Edit Limit Version 7.x-1.0 Update beta2
Quade ≫ Edit Limit Version 7.x-1.0 Update beta3
Quade ≫ Edit Limit Version 7.x-1.0 Update beta4
Quade ≫ Edit Limit Version 7.x-1.1
Quade ≫ Edit Limit Version 7.x-1.2
Quade ≫ Edit Limit Version 7.x-1.x Update dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.56% | 0.719 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://osvdb.org/93725
http://seclists.org/fulldisclosure/2013/May/208
http://secunia.com/advisories/53556
http://www.openwall.com/lists/oss-security/2013/05/29/9
http://www.securityfocus.com/bid/60209
https://drupal.org/node/2006188
https://drupal.org/node/2007048
https://exchange.xforce.ibmcloud.com/vulnerabilities/84630