CVE-2013-1925
16.07.2013, 18:55
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.Enginsight
Vendor | Product | Version |
---|---|---|
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.0:x |
chaos_tool_suite_project | ctools | 7.x-1.1:x |
chaos_tool_suite_project | ctools | 7.x-1.2:x |
chaos_tool_suite_project | ctools | 7.x-1.x:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References