CVE-2012-4498
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restrictions and possibly have other unspecified impact.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://drupal.org/node/1762160
Vendor advisory: secalert@redhat.com — http://drupal.org/node/1762152
References
- http://drupal.org/node/1762152
- http://drupal.org/node/1762160
- http://www.openwall.com/lists/oss-security/2012/10/04/6
- http://www.openwall.com/lists/oss-security/2012/10/07/1
- http://drupal.org/node/1762152
- http://drupal.org/node/1762160
- http://www.openwall.com/lists/oss-security/2012/10/04/6
- http://www.openwall.com/lists/oss-security/2012/10/07/1
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.