1 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 29EXPL: 0

28 Aug 2013 — The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors. El módulo de acceso de referencia al usuario Node 6.x-3.x anteior a 6.x-3.5 y 7.x-3.x anteior a 7.x-3.10 para Drupal no restringe adecuadamente el acceso al contenid... • http://www.openwall.com/lists/oss-security/2013/05/29/9 • CWE-264: Permissions, Privileges, and Access Controls •