SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-0226

The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to read nodes or (2) remote authenticated users with the…

MEDIUM 6.0EPSS 0.95%

Does this matter?

Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.

Description

The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to read nodes or (2) remote authenticated users with the "admin shortcuts" permission to read, edit, or delete nodes via unspecified vectors.

CVSS 2.0
6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
0.95% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
zugec ivan/keyboard shortcut utility
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.