CVE-2013-0245
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access…
Does this matter?
Lower severity and a low EPSS score (1.89%). Track it; it rarely justifies an emergency change on its own.
Description
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
- CVSS 2.0
- 2.1 LOWAV:N/AC:H/Au:S/C:P/I:N/A:N
- EPSS
- 1.89% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- drupal/drupal
- Source
- secalert@redhat.com
References
- http://osvdb.org/89305
- http://packetstormsecurity.com/files/119598/Drupal-Core-6.x-7.x-Cross-Site-Scripting-Access-Bypass.html
- http://seclists.org/fulldisclosure/2013/Jan/120
- http://seclists.org/oss-sec/2013/q1/211
- http://secunia.com/advisories/51717Vendor Advisory
- http://www.debian.org/security/2013/dsa-2776
- https://drupal.org/SA-CORE-2013-001Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81380
- http://osvdb.org/89305
- http://packetstormsecurity.com/files/119598/Drupal-Core-6.x-7.x-Cross-Site-Scripting-Access-Bypass.html
- http://seclists.org/fulldisclosure/2013/Jan/120
- http://seclists.org/oss-sec/2013/q1/211
- http://secunia.com/advisories/51717Vendor Advisory
- http://www.debian.org/security/2013/dsa-2776
- https://drupal.org/SA-CORE-2013-001Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81380
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.