4.9
CVSSv2

CVE-2013-4445

Published: 07/12/2013 Updated: 09/12/2013
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

The json rendering functionality in the Context module 6.x-2.x prior to 6.x-3.2 and 7.x-3.x prior to 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

steven_jones context 7.x-3.0

steven_jones context 6.x-3.x

steven_jones context 6.x-3.0

steven_jones context 6.x-2.0

steven_jones context 7.x-3.x

steven_jones context 6.x-3.1