PT-2013-5889 · Drupal · Node View Permissions

Publicado

2013-09-30

·

Atualizado

2014-05-05

·

CVE-2013-5965

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Node View Permissions module versions 7.x-1.x through 7.x-1.1
Description The issue is related to the improper implementation of the hook query alter function in the Node View Permissions module for Drupal. This might allow remote attackers to obtain sensitive information by reading a node listing.
Recommendations For Node View Permissions module versions 7.x-1.x through 7.x-1.1, update to version 7.x-1.2 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-5965

Produtos afetados

Node View Permissions