Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfp3-hjq5-f86q

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.

EPSS

Процентиль: 63%
0.0045
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.

EPSS

Процентиль: 63%
0.0045
Низкий