CVE-2012-4500: Low severity Nancy Wichmann Announcements vulnerability
Published Oct 31, 2012
·Updated
The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node access restrictions and possibly have other unspecified impact.
Affected Software
8 affected components
Nancy Wichmann Announcements=6.x-1.0
Nancy Wichmann Announcements=6.x-1.0-beta
Nancy Wichmann Announcements=6.x-1.1
Nancy Wichmann Announcements=6.x-1.2
Nancy Wichmann Announcements=6.x-1.3
Nancy Wichmann Announcements=6.x-1.4
Nancy Wichmann Announcements=6.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Event History
Oct 31, 2012
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4500?
CVE-2012-4500 is classified as a moderate vulnerability due to potential unauthorized access to node content.
2
How do I fix CVE-2012-4500?
To fix CVE-2012-4500, update the Announcements module to version 6.x-1.5 or later.
3
Who is affected by CVE-2012-4500?
CVE-2012-4500 affects users of the Announcements module versions 6.x-1.0 to 6.x-1.4 for Drupal.
4
Can CVE-2012-4500 be exploited by unauthenticated users?
No, CVE-2012-4500 requires authenticated users with the 'access announcements' permission to exploit the vulnerability.
5
What type of impact does CVE-2012-4500 have?
CVE-2012-4500 may allow remote authenticated users to bypass node access restrictions and access restricted content.