5
CVSSv2

CVE-2012-4488

Published: 31/10/2012 Updated: 02/11/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Location module 6.x prior to 6.x-3.2 and 7.x prior to 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows remote malicious users to read node or user results via the location search page.

Vulnerable Product Search on Vulmon Subscribe to Product

location_module_project location 7.x-4.x

location_module_project location 7.x-3.x

location_module_project location 6.x-3.1

location_module_project location 6.x-3.0

location_module_project location 6.x-3.x

location_module_project location 7.x-5.x

location_module_project location 7.x-1.0