Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrx6-v2w3-g566

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.

The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.

EPSS

Процентиль: 58%
0.00364
Низкий

Связанные уязвимости

nvd
больше 15 лет назад

The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.

EPSS

Процентиль: 58%
0.00364
Низкий