CVE-2013-1925 Information
Feb 14, 2021
cve
Description
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access which allows remote authenticated users with the \access content\ permission to read restricted node titles via an autocomplete list.
Reference
http://osvdb.org/91986 http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.html http://seclists.org/fulldisclosure/2013/Apr/8 https://drupal.org/node/1960406 https://drupal.org/node/1960424 https://exchange.xforce.ibmcloud.com/vulnerabilities/83254
Share on: