RSS   Vulnerabilities for 'Multilink'   RSS

2012-12-26
 
CVE-2012-5589

 

 
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.

 


Copyright 2024, cxsecurity.com

 

Back to Top