VulnerabilityModified
CVE-2013-2122
The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.
MEDIUM 5.0EPSS 1.56%
Does this matter?
Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.
Description
The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- quade/edit limit
- Source
- secalert@redhat.com
References
- http://osvdb.org/93725
- http://seclists.org/fulldisclosure/2013/May/208
- http://secunia.com/advisories/53556Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/05/29/9
- http://www.securityfocus.com/bid/60209
- https://drupal.org/node/2006188Vendor Advisory
- https://drupal.org/node/2007048Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84630
- http://osvdb.org/93725
- http://seclists.org/fulldisclosure/2013/May/208
- http://secunia.com/advisories/53556Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/05/29/9
- http://www.securityfocus.com/bid/60209
- https://drupal.org/node/2006188Vendor Advisory
- https://drupal.org/node/2007048Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84630
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.