The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/52996 | third party advisory |
https://drupal.org/node/1971848 | patch |
http://osvdb.org/92532 | vdb entry |
https://drupal.org/node/1972976 | patch vendor advisory |
https://drupal.org/node/1971856 | patch |