CVE-2007-4436: Medium severity Drupal Project issue tracking module vulnerability
The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page; (2) obtain project names via unspecified vectors; (3) obtain sensitive information via the statistics pages; and (4) read CVS project activity.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4436?
CVE-2007-4436 is considered a moderate severity vulnerability due to improper permission enforcement.
How do I fix CVE-2007-4436?
To fix CVE-2007-4436, upgrade the affected Drupal Project module to version 5.x-1.0 or above.
What are the impacts of CVE-2007-4436?
CVE-2007-4436 allows remote attackers to obtain sensitive information through the Tracker Module and Recent posts page.
Which versions of Drupal are affected by CVE-2007-4436?
CVE-2007-4436 affects Drupal Project module versions before 5.x-1.0 and applicable versions of Project issue tracking module.
Can CVE-2007-4436 be exploited remotely?
Yes, CVE-2007-4436 can be exploited remotely by attackers to gain unauthorized access to sensitive information.