4
CVSSv2

CVE-2013-1973

Published: 09/06/2014 Updated: 24/06/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x prior to 6.x-1.4 and 7.x-1.x prior to 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

autocomplete widgets project autocomplete widgets 7.x-1.x

autocomplete widgets project autocomplete widgets 6.x-1.1

autocomplete widgets project autocomplete widgets 6.x-1.2

autocomplete widgets project autocomplete widgets 6.x-1.3

autocomplete widgets project autocomplete widgets 6.x-1.0