CVE-2012-5589: Infoleak
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5589?
CVE-2012-5589 has been rated as a moderate severity vulnerability due to improper node permission checks.
How do I fix CVE-2012-5589?
To fix CVE-2012-5589, upgrade to MultiLink module version 6.x-2.7 or 7.x-2.7 or later.
What software versions are affected by CVE-2012-5589?
CVE-2012-5589 affects MultiLink module versions 6.x-2.0 through 6.x-2.6 and 7.x-2.x-dev.
Who can exploit CVE-2012-5589?
Remote authenticated users with text-editing permissions can exploit CVE-2012-5589 to read arbitrary node titles.
Is there a patch available for CVE-2012-5589?
Yes, the patch is included in the update for MultiLink module versions 6.x-2.7 and 7.x-2.7.