CVE-2013-4230
The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted…
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- monster menus project/monster menus
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/54391Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/08/10/1
- http://www.securityfocus.com/bid/61711
- https://drupal.org/node/2059805Patch
- https://drupal.org/node/2059807Patch
- https://drupal.org/node/2059823Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86326
- http://secunia.com/advisories/54391Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/08/10/1
- http://www.securityfocus.com/bid/61711
- https://drupal.org/node/2059805Patch
- https://drupal.org/node/2059807Patch
- https://drupal.org/node/2059823Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86326
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.