VulnerabilityModified
CVE-2014-9154
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.
MEDIUM 4.0EPSS 0.94%
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- notify project/notify
- Source
- cve@mitre.org
References
- https://www.drupal.org/node/2320693Patch
- https://www.drupal.org/node/2320741Vendor Advisory
- https://www.drupal.org/node/2320693Patch
- https://www.drupal.org/node/2320741Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.