VulnerabilityModified
CVE-2009-3122
The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.
MEDIUM 6.4EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- chris shattuck/ajaxtable
- Source
- cve@mitre.org
References
- http://drupal.org/node/560298Vendor Advisory
- http://secunia.com/advisories/36497Vendor Advisory
- http://www.osvdb.org/57435
- http://www.securityfocus.com/bid/36165
- http://www.vupen.com/english/advisories/2009/2452Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52818
- http://drupal.org/node/560298Vendor Advisory
- http://secunia.com/advisories/36497Vendor Advisory
- http://www.osvdb.org/57435
- http://www.securityfocus.com/bid/36165
- http://www.vupen.com/english/advisories/2009/2452Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52818
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.