6.4
CVE-2013-4379
- EPSS 1.36%
- Veröffentlicht 09.10.2013 17:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sebastien Corbin ≫ Make Meeting Scheduler Module Version6.x-1.0
Sebastien Corbin ≫ Make Meeting Scheduler Module Version6.x-1.1
Sebastien Corbin ≫ Make Meeting Scheduler Module Version6.x-1.2
Sebastien Corbin ≫ Make Meeting Scheduler Module Version6.x-1.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.36% | 0.681 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
http://secunia.com/advisories/54634
http://www.openwall.com/lists/oss-security/2013/09/27/6
https://drupal.org/node/2081637
https://drupal.org/node/2081647