PT-2010-3938 · Drupal · Node Reference Module+2
Published
2010-06-21
·
Updated
2017-08-17
·
CVE-2010-2353
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Content Construction Kit (CCK) module versions 6.x before 6.x-2.7
Description
The issue concerns the Node Reference module in the CCK module for Drupal. It does not perform access checks for the source field in the backend URL for the autocomplete widget. This allows remote attackers to discover titles and IDs of controlled nodes.
Recommendations
For versions prior to 6.x-2.7, update to version 6.x-2.7 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Content Construction Kit (Cck) Module
Drupal
Node Reference Module