4.9
CVE-2013-4445
- EPSS 0.55%
- Veröffentlicht 07.12.2013 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Steven Jones ≫ Context Version6.x-2.0 Updatealpha1
Steven Jones ≫ Context Version6.x-2.0 Updatealpha2
Steven Jones ≫ Context Version6.x-2.0 Updatebeta1
Steven Jones ≫ Context Version6.x-2.0 Updatebeta2
Steven Jones ≫ Context Version6.x-2.0 Updatebeta3
Steven Jones ≫ Context Version6.x-2.0 Updatebeta4
Steven Jones ≫ Context Version6.x-2.0 Updatebeta5
Steven Jones ≫ Context Version6.x-2.0 Updatebeta6
Steven Jones ≫ Context Version6.x-2.0 Updatebeta7
Steven Jones ≫ Context Version6.x-2.0 Updaterc1
Steven Jones ≫ Context Version6.x-2.0 Updaterc2
Steven Jones ≫ Context Version6.x-2.0 Updaterc3
Steven Jones ≫ Context Version6.x-3.0
Steven Jones ≫ Context Version6.x-3.0 Updatealpha1
Steven Jones ≫ Context Version6.x-3.0 Updatealpha2
Steven Jones ≫ Context Version6.x-3.0 Updatebeta1
Steven Jones ≫ Context Version6.x-3.0 Updatebeta2
Steven Jones ≫ Context Version6.x-3.0 Updatebeta3
Steven Jones ≫ Context Version6.x-3.0 Updatebeta4
Steven Jones ≫ Context Version6.x-3.0 Updatebeta5
Steven Jones ≫ Context Version6.x-3.0 Updatebeta6
Steven Jones ≫ Context Version6.x-3.0 Updatebeta7
Steven Jones ≫ Context Version6.x-3.0 Updatebeta8
Steven Jones ≫ Context Version6.x-3.0 Updaterc1
Steven Jones ≫ Context Version6.x-3.0 Updaterc2
Steven Jones ≫ Context Version6.x-3.1
Steven Jones ≫ Context Version6.x-3.x Updatedev
Steven Jones ≫ Context Version7.x-3.0 Updatealpha1
Steven Jones ≫ Context Version7.x-3.0 Updatealpha2
Steven Jones ≫ Context Version7.x-3.0 Updatealpha3
Steven Jones ≫ Context Version7.x-3.0 Updatebeta1
Steven Jones ≫ Context Version7.x-3.0 Updatebeta2
Steven Jones ≫ Context Version7.x-3.0 Updatebeta3
Steven Jones ≫ Context Version7.x-3.0 Updatebeta4
Steven Jones ≫ Context Version7.x-3.0 Updatebeta5
Steven Jones ≫ Context Version7.x-3.0 Updatebeta6
Steven Jones ≫ Context Version7.x-3.0 Updatebeta7
Steven Jones ≫ Context Version7.x-3.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.654 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 6.8 | 4.9 |
AV:N/AC:M/Au:S/C:P/I:P/A:N
|