Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q799-3qfw-88p4

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restrictions when constructing SQL queries, which allows remote attackers to read restricted node listings via unspecified vectors.

The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restrictions when constructing SQL queries, which allows remote attackers to read restricted node listings via unspecified vectors.

EPSS

Процентиль: 68%
0.00595
Низкий

Связанные уязвимости

nvd
больше 15 лет назад

The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restrictions when constructing SQL queries, which allows remote attackers to read restricted node listings via unspecified vectors.

EPSS

Процентиль: 68%
0.00595
Низкий