MEDIUM
The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information via the recent comments listing
Published Oct 31, 2012
5.0
MEDIUMCVSS 2.0
EPSS 1.37%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.