The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/39884 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/58724 | vdb entry |
http://seclists.org/fulldisclosure/2010/May/272 | mailing list |
http://drupal.org/node/803944 | patch vendor advisory |
http://www.securityfocus.com/bid/40285 | vdb entry patch |
http://www.madirish.net/?article=458 |