PT-2011-3272 · Drupal · Node Quick Find
Published
2011-04-10
·
Updated
2017-08-17
·
CVE-2011-1661
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Node Quick Find module version 6.x-1.1
Description
The issue allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature, due to the module not using db rewrite sql when presenting node titles.
Recommendations
For Node Quick Find module version 6.x-1.1, consider disabling the autocomplete feature until a patch is available to prevent the bypassing of access restrictions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node Quick Find