The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/93725 - | |
References | () http://seclists.org/fulldisclosure/2013/May/208 - | |
References | () http://secunia.com/advisories/53556 - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2013/05/29/9 - | |
References | () http://www.securityfocus.com/bid/60209 - | |
References | () https://drupal.org/node/2006188 - Vendor Advisory | |
References | () https://drupal.org/node/2007048 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/84630 - |
Information
Published : 2013-07-16 18:55
Updated : 2024-11-21 01:51
NVD link : CVE-2013-2122
Mitre link : CVE-2013-2122
CVE.ORG link : CVE-2013-2122
JSON object : View
Products Affected
drupal
- drupal
quade
- edit_limit
CWE
CWE-264
Permissions, Privileges, and Access Controls