PT-2013-2169 · Drupal · Keyboard Shortcut Utility
Published
2013-03-19
·
Updated
2013-03-21
·
CVE-2013-0226
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Keyboard Shortcut Utility module versions 7.x-1.x before 7.x-1.1
Description
The issue concerns the Keyboard Shortcut Utility module for Drupal, where it fails to properly check node restrictions. This allows remote authenticated users with specific permissions to access nodes in unauthorized ways. For users with the
view shortcuts permission, it enables reading nodes. For users with the admin shortcuts permission, it allows reading, editing, or deleting nodes.Recommendations
For Keyboard Shortcut Utility module versions 7.x-1.x before 7.x-1.1, update to version 7.x-1.1 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keyboard Shortcut Utility