PT-2010-3938 · Drupal · Node Reference Module+2

Published

2010-06-21

·

Updated

2017-08-17

·

CVE-2010-2353

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Content Construction Kit (CCK) module versions 6.x before 6.x-2.7
Description The issue concerns the Node Reference module in the CCK module for Drupal. It does not perform access checks for the source field in the backend URL for the autocomplete widget. This allows remote attackers to discover titles and IDs of controlled nodes.
Recommendations For versions prior to 6.x-2.7, update to version 6.x-2.7 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2353

Affected Products

Content Construction Kit (Cck) Module
Drupal
Node Reference Module