MEDIUM
The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors
Published Aug 21, 2013
6.0
MEDIUMCVSS 2.0
EPSS 1.21%
Description
The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors.
Affected products
No data.
AND
OR
- 6.x-6.19
- 6.x-6.22
- 6.x-6.23
- 6.x-6.24
- 6.x-6.25
- 6.x-6.26
- 6.x-6.27
- 6.x-6.29
- 6.x-6.30
- 6.x-6.31
- 6.x-6.32
- 6.x-6.33
- 6.x-6.34
- 6.x-6.35
- 6.x-6.36
- 6.x-6.37
- 6.x-6.38
- 6.x-6.41
- 6.x-6.42
- 6.x-6.43
- 6.x-6.44
- 6.x-6.48
- 6.x-6.53
- 6.x-6.56
- 6.x-6.57
- 6.x-6.59
- 6.x-6.60
- 7.x-1.0
- 7.x-1.1
- 7.x-1.2
- 7.x-1.3
- 7.x-1.4
- 7.x-1.5
- 7.x-1.6
- 7.x-1.7
- 7.x-1.8
- 7.x-1.9
- 7.x-1.10
- 7.x-1.11
- 7.x-1.12
- 7.x-1.x
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://secunia.com/advisories/54391 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.openwall.com/lists/oss-security/2013/08/10/1 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/61711 vdb-entryx_refsource_BID
- https://drupal.org/node/2059805 x_refsource_CONFIRMPatch
- https://drupal.org/node/2059807 x_refsource_CONFIRMPatch
- https://drupal.org/node/2059823 x_refsource_MISCVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86326 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/54391 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.openwall.com/lists/oss-security/2013/08/10/1 | mailing-listx_refsource_MLIST | |
| http://www.securityfocus.com/bid/61711 | vdb-entryx_refsource_BID | |
| https://drupal.org/node/2059805 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/2059807 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/2059823 | x_refsource_MISCVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/86326 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 21, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4230
CISA Vulnrichment
Updated n/a