Entity Api Project

Entity Api

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Published 10.04.2018 15:29:00
  • Last modified 21.11.2024 02:04:12

The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.

  • EPSS 0.31%
  • Published 10.04.2018 15:29:00
  • Last modified 21.11.2024 02:04:13

The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.

  • EPSS 0.38%
  • Published 10.04.2018 15:29:00
  • Last modified 21.11.2024 02:04:13

The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.

  • EPSS 0.21%
  • Published 03.03.2015 19:59:03
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.

  • EPSS 0.2%
  • Published 19.07.2014 18:55:01
  • Last modified 12.04.2025 10:46:40

The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was SPLIT per ADT5 due to differen...

  • EPSS 0.28%
  • Published 19.07.2014 18:55:01
  • Last modified 12.04.2025 10:46:40

The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NOTE: this identifier was SPLIT ...