TROYANOSYVIRUS
Back to CVEs

CVE-2012-1635

N/A

Description

The hook_node_access function in the revisioning module 7.x-1.x before 7.x-1.3 for Drupal checks the permissions of the current user even when it is called to check permissions of other users, which allows remote attackers to bypass intended access restrictions, as demonstrated when using the XML sitemap module to obtain sensitive information about unpublished content.

CVE Details

CVSS v3.1 ScoreN/A
Published8/28/2012
Last Modified4/11/2025
Sourcenvd
Honeypot Sightings0

Affected Products

drupal:drupalrik_de_boer:revisioning

Weaknesses (CWE)

CWE-264

References

http://drupal.org/node/1407456(secalert@redhat.com)
https://drupal.org/node/1409268(secalert@redhat.com)
http://drupal.org/node/1407456(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2012/04/07/1(af854a3a-2127-422b-91ae-364da2661108)
https://drupal.org/node/1409268(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.