Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qm2x-gh76-6m45

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node.

The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node.

EPSS

Процентиль: 47%
0.00237
Низкий

Связанные уязвимости

nvd
около 16 лет назад

The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node.

EPSS

Процентиль: 47%
0.00237
Низкий