cbcvebase.

Entity Api Project Entity Api vulnerabilities

6 known vulnerabilities affecting entity_api_project/entity_api.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2014-1398P3MEDIUMCVSS 6.5v7.x-1.0v7.x-1.1+1 more2018-04-10
CVE-2014-1398 [MEDIUM] CWE-284 CVE-2014-1398: The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.
nvd
CVE-2014-1400P3MEDIUMCVSS 6.5v7.x-1.0v7.x-1.1+1 more2018-04-10
CVE-2014-1400 [MEDIUM] CWE-284 CVE-2014-1400: The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
nvd
CVE-2014-1399P3MEDIUMCVSS 6.5v7.x-1.0v7.x-1.1+1 more2018-04-10
CVE-2014-1399 [MEDIUM] CWE-284 CVE-2014-1399: The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
nvd
CVE-2013-7391P4MEDIUMCVSS 5.0≤ 7.x-1.1v7.x-1.02014-07-19
CVE-2013-7391 [MEDIUM] CVE-2013-7391: The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5 due to different researcher organizations.
nvd
CVE-2013-4273P4MEDIUMCVSS 4.0v7.x-1.0v7.x-1.12014-07-19
CVE-2013-4273 [MEDIUM] CWE-264 CVE-2013-4273: The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node co The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was SPLIT per ADT5 due to different researcher organizations. CVE-2013-7391 was assigned for the View vector.
nvd
CVE-2015-2197P4LOWCVSS 3.5≤ 7.x-1.52015-03-03
CVE-2015-2197 [LOW] CWE-79 CVE-2015-2197: Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows r Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.
nvd
Entity Api Project Entity Api vulnerabilities | cvebase