First published: Wed Oct 31 2012(Updated: )
The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attackers to access restricted nodes via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Earl Dunovant Monthly Archive By Node Type | =6.x-1.0 | |
Earl Dunovant Monthly Archive By Node Type | =6.x-2.0 | |
Earl Dunovant Monthly Archive By Node Type | =6.x-3.0 | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-4491 is considered to be medium due to the unauthorized access it allows to restricted nodes.
To fix CVE-2012-4491, upgrade the Monthly Archive by Node Type module to version 6.x-3.0 or later.
CVE-2012-4491 affects users of the Monthly Archive by Node Type module versions 6.x-1.0 and 6.x-2.0 in Drupal.
CVE-2012-4491 enables remote attackers to access restricted nodes without proper permissions.
Yes, there are known exploits that allow attackers to leverage CVE-2012-4491 to bypass node access controls.