CVE-2013-1925
published 2013-07-16CVE-2013-1925: The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the…
PriorityP418low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
1.77%
75.7th percentile
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/91986http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.htmlhttp://seclists.org/fulldisclosure/2013/Apr/8https://drupal.org/node/1960406https://drupal.org/node/1960424https://exchange.xforce.ibmcloud.com/vulnerabilities/83254http://osvdb.org/91986http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.htmlhttp://seclists.org/fulldisclosure/2013/Apr/8https://drupal.org/node/1960406https://drupal.org/node/1960424https://exchange.xforce.ibmcloud.com/vulnerabilities/83254
2013-07-16
Published