The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://drupalcode.org/project/node_embed.git/commitdiff/d06f022 | patch exploit |
http://drupal.org/node/1618430 | patch |
http://www.osvdb.org/82735 | vdb entry |
http://www.securityfocus.com/bid/53835 | vdb entry |
http://www.openwall.com/lists/oss-security/2012/06/14/3 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/76148 | vdb entry |
http://drupal.org/node/1618428 | patch |
http://secunia.com/advisories/48348 | third party advisory vendor advisory |
http://drupal.org/node/1619824 | patch vendor advisory |
http://drupalcode.org/project/node_embed.git/commitdiff/7a2296c | patch exploit |