PT-2012-5437 · Drupal · The Monthly Archive By Node Type
Joshua Brauer
·
Published
2012-10-31
·
Updated
2013-03-02
·
CVE-2012-4491
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
The Monthly Archive by Node Type module version 6.x for Drupal
Description
The issue is related to improper permission checking by the module, allowing remote attackers to access restricted nodes.
Recommendations
For The Monthly Archive by Node Type module version 6.x, consider disabling the module until a patch is available to prevent unauthorized access to restricted nodes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Monthly Archive By Node Type