6

CVE-2013-4230

The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Monster Menus ProjectMonster Menus Version6.x-6.19
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.22
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.23
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.24
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.25
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.26
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.27
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.29
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.30
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.31
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.32
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.33
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.34
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.35
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.36
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.37
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.38
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.41
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.42
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.43
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.44
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.48
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.53
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.56
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.57
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.59
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version6.x-6.60
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.0
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.1
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.2
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.3
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.4
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.5
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.6
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.7
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.8
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.9
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.10
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.11
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.12
   DrupalDrupal Version-
Monster Menus ProjectMonster Menus Version7.x-1.x Updatedev
   DrupalDrupal Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/54391
Vendor Advisory
http://www.openwall.com/lists/oss-security/2013/08/10/1
https://drupal.org/node/2059823
Vendor Advisory
http://www.securityfocus.com/bid/61711
https://drupal.org/node/2059805
Patch
https://drupal.org/node/2059807
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/86326