CVE-2013-1925
low
CVSS v3
—
CVSS v2
3.5
VIR risk
3.5
Description
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://drupal.org/node/1960424
Vendor advisory: secalert@redhat.com — https://drupal.org/node/1960406
References
- http://osvdb.org/91986
- http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.html
- http://seclists.org/fulldisclosure/2013/Apr/8
- https://drupal.org/node/1960406
- https://drupal.org/node/1960424
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83254
- http://osvdb.org/91986
- http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.html
- http://seclists.org/fulldisclosure/2013/Apr/8
- https://drupal.org/node/1960406
- https://drupal.org/node/1960424
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83254
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.