CVE-2013-2123

The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.3:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.4:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.x:dev:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.8:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.9:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.0:rc4:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.0:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.2:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.6:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.0:rc6:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.0:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.5:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.0:rc5:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.0:rc5:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.1:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.3:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.0:rc4:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.7:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.2:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.1:*:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:6.x-3.x:dev:*:*:*:*:*:*
cpe:2.3:a:node_access_user_reference_project:nodeaccess_userreference_module:7.x-3.4:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

Information

Published : 2013-08-28 15:55

Updated : 2013-10-07 10:48


NVD link : CVE-2013-2123

Mitre link : CVE-2013-2123


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

drupal

  • drupal

node_access_user_reference_project

  • nodeaccess_userreference_module