VulnerabilityModified
CVE-2012-4471
The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the priority order via unspecified vectors.
MEDIUM 5.0EPSS 1.33%
Does this matter?
Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.
Description
The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the priority order via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.33% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- dominique clause/search autocomplete
- Source
- secalert@redhat.com
References
- http://drupal.org/node/1649442Patch
- http://drupal.org/node/1679422Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/10/04/3
- http://www.securityfocus.com/bid/54379
- http://drupal.org/node/1649442Patch
- http://drupal.org/node/1679422Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/10/04/3
- http://www.securityfocus.com/bid/54379
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.