PT-2011-3272 · Drupal · Node Quick Find

Published

2011-04-10

·

Updated

2017-08-17

·

CVE-2011-1661

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Node Quick Find module version 6.x-1.1
Description The issue allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature, due to the module not using db rewrite sql when presenting node titles.
Recommendations For Node Quick Find module version 6.x-1.1, consider disabling the autocomplete feature until a patch is available to prevent the bypassing of access restrictions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1661

Affected Products

Node Quick Find