The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2013-07-16 11:55
Updated : 2017-08-28 18:33
NVD link : CVE-2013-0245
Mitre link : CVE-2013-0245
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
drupal
- drupal