PT-2013-2169 · Drupal · Keyboard Shortcut Utility
Publicado
2013-03-19
·
Atualizado
2013-03-21
·
CVE-2013-0226
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Keyboard Shortcut Utility module versions 7.x-1.x before 7.x-1.1
Description
The issue concerns the Keyboard Shortcut Utility module for Drupal, where it fails to properly check node restrictions. This allows remote authenticated users with specific permissions to access nodes in unauthorized ways. For users with the
view shortcuts permission, it enables reading nodes. For users with the admin shortcuts permission, it allows reading, editing, or deleting nodes.Recommendations
For Keyboard Shortcut Utility module versions 7.x-1.x before 7.x-1.1, update to version 7.x-1.1 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Keyboard Shortcut Utility