CVE-2009-4558
The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages,…
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body of an arbitrary node via unknown vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- unleashedmind/img assist
- Source
- cve@mitre.org
References
- http://drupal.org/node/520564Patch, Vendor Advisory
- http://osvdb.org/55867
- http://secunia.com/advisories/35879Vendor Advisory
- http://www.securityfocus.com/bid/35710Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51787
- http://drupal.org/node/520564Patch, Vendor Advisory
- http://osvdb.org/55867
- http://secunia.com/advisories/35879Vendor Advisory
- http://www.securityfocus.com/bid/35710Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51787
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.