The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote attackers to bypass access restrictions via a node listing.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://drupal.org/node/2125239 | patch |
http://www.securityfocus.com/bid/63568 | vdb entry |
http://secunia.com/advisories/55255 | third party advisory |
https://drupal.org/node/2129379 | patch vendor advisory |