CVE-2013-0226

The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to read nodes or (2) remote authenticated users with the "admin shortcuts" permission to read, edit, or delete nodes via unspecified vectors.
Severity
UNKNOWN
AV:N/AC:M/Au:S/C:P/I:P/A:P
Atk. Vector
NETWORK
Atk. Complexity
MEDIUM
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
zugec_ivankeyboard_shortcut_utility
7.x-1.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration