CVE-2013-2247
The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit form.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- fast permissions administration project/fast permission administration
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2013/07/06/3
- https://drupal.org/node/2028417Patch
- https://drupal.org/node/2028421Patch
- https://drupal.org/node/2028813Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/07/06/3
- https://drupal.org/node/2028417Patch
- https://drupal.org/node/2028421Patch
- https://drupal.org/node/2028813Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.