MEDIUM
The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors
Published Aug 28, 2013
5.8
MEDIUMCVSS 2.0
EPSS 1.31%
Description
The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.
Affected products
No data.
AND
OR
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.0
- 6.x-3.1
- 6.x-3.2
- 6.x-3.3
- 6.x-3.4
- 6.x-3.x
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.0
- 7.x-3.1
- 7.x-3.2
- 7.x-3.3
- 7.x-3.4
- 7.x-3.5
- 7.x-3.6
- 7.x-3.7
- 7.x-3.8
- 7.x-3.9
- 7.x-3.x
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www.openwall.com/lists/oss-security/2013/05/29/9 mailing-listx_refsource_MLIST
- https://drupal.org/node/2007072 x_refsource_CONFIRMPatch
- https://drupal.org/node/2007078 x_refsource_CONFIRMPatch
- https://drupal.org/node/2007122 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2013/05/29/9 | mailing-listx_refsource_MLIST | |
| https://drupal.org/node/2007072 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/2007078 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/2007122 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 28, 2013
Updated Sep 17, 2024
Reserved Feb 19, 2013
Link CVE-2013-2123
CISA Vulnrichment
Updated n/a