CVE-2012-5589
26.12.2012, 17:55
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.Enginsight
Vendor | Product | Version |
---|---|---|
netgenius | multilink | 6.x-2.0:x |
netgenius | multilink | 6.x-2.1:x |
netgenius | multilink | 6.x-2.2:x |
netgenius | multilink | 6.x-2.3:x |
netgenius | multilink | 6.x-2.4:x |
netgenius | multilink | 6.x-2.5:x |
netgenius | multilink | 6.x-2.6:x |
netgenius | multilink | 7.x-2.x:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References