6.5
CVE-2014-9503
- EPSS 0.21%
- Veröffentlicht 01.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 02:21:02
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open Atrium Project ≫ Open Atrium SwPlatformdrupal Version >= 7.x-2.0 < 7.x-2.26
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatealpha1 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatealpha2 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatealpha3 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatealpha4 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatealpha5 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatebeta1 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatebeta2 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatebeta3 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updatebeta4 SwPlatformdrupal
Open Atrium Project ≫ Open Atrium Version7.x-2.0 Updaterc1 SwPlatformdrupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.435 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:P
|