Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52r3-f6x8-h7v5

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.

The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.

EPSS

Процентиль: 53%
0.00297
Низкий

Связанные уязвимости

nvd
около 14 лет назад

The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.

EPSS

Процентиль: 53%
0.00297
Низкий