The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2013-07-16 11:55
Updated : 2017-08-28 18:33
NVD link : CVE-2013-2122
Mitre link : CVE-2013-2122
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
drupal
- drupal
quade
- edit_limit