5.8

CVE-2013-2123

The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Node Access User Reference ProjectNodeaccess Userreference Module Version6.x-3.0 Updaterc1
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version6.x-3.0 Updaterc2
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version6.x-3.0 Updaterc3
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version6.x-3.0 Updaterc4
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version6.x-3.0 Updaterc5
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version6.x-3.0 Updaterc6
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version6.x-3.x Updatedev
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version7.x-3.0 Updaterc1
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version7.x-3.0 Updaterc2
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version7.x-3.0 Updaterc3
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version7.x-3.0 Updaterc4
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version7.x-3.0 Updaterc5
   DrupalDrupal Version-
Node Access User Reference ProjectNodeaccess Userreference Module Version7.x-3.x Updatedev
   DrupalDrupal Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.652
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.