First published: Wed Jun 18 2008(Updated: )
The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permissions to bypass restrictions and modify the node hierarchy via unspecified attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | =5.0 | |
Drupal | =6.0 | |
Drupal Node Hierarchy Module | =5 | |
Drupal Node Hierarchy Module | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2771 is categorized as a moderate severity vulnerability due to its potential for abuse by users with access permissions.
To fix CVE-2008-2771, update the Node Hierarchy module to the latest version available, either 5.x-1.1 or 6.x-1.0.
CVE-2008-2771 affects users of the Node Hierarchy module versions 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal.
Attackers exploiting CVE-2008-2771 can modify the node hierarchy, potentially leading to unauthorized changes in content organization.
CVE-2008-2771 impacts Drupal versions 5.0 and 6.0 due to improper access checks in the Node Hierarchy module.