CVE-2011-2687

EUVD-2022-3306
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
drupaldrupal
7.0
drupaldrupal
7.0:alpha1
drupaldrupal
7.0:alpha2
drupaldrupal
7.0:alpha3
drupaldrupal
7.0:alpha4
drupaldrupal
7.0:alpha5
drupaldrupal
7.0:alpha6
drupaldrupal
7.0:alpha7
drupaldrupal
7.0:beta1
drupaldrupal
7.0:beta2
drupaldrupal
7.0:beta3
drupaldrupal
7.0:dev
drupaldrupal
7.0:rc1
drupaldrupal
7.0:rc2
drupaldrupal
7.0:rc3
drupaldrupal
7.0:rc4
drupaldrupal
7.1
drupaldrupal
7.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
drupal6
hardy
dne
lucid
not-affected
maverick
not-affected
natty
not-affected
drupal7
hardy
dne
lucid
dne
maverick
dne
natty
dne
Common Weakness Enumeration