1 results (0.015 seconds)

CVSS: 4.3EPSS: 0%CPEs: 7EXPL: 0

The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed. El módulo Feeds v7.x-2.x antes de v7.x-2.0-alpha6 para Drupal, cuando un campo está mapeado al nodo del autor, no comprueba adecuadamente los permisos, lo que permite a atacantes remotos crear nodos arbitrarios a través de un origen manipulado. • http://drupal.org/node/1808832 http://drupalcode.org/project/feeds.git/commitdiff/a538c20 http://www.openwall.com/lists/oss-security/2012/11/20/4 • CWE-264: Permissions, Privileges, and Access Controls •