CVE-2013-4597 Information

Description

The Revisioning module 7.x-1.x before 7.x-1.6 for Drupal does not properly check node access permissions for content marked unpublished by the Scheduled module which allows remote authenticated users to obtain sensitive information via unspecified vectors.

Reference

http://seclists.org/oss-sec/2013/q4/317 https://drupal.org/node/2133555 https://drupal.org/node/2135257

Share on: