First published: Wed Dec 26 2012(Updated: )
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netgenius Multilink | =6.x-2.0 | |
Netgenius Multilink | =6.x-2.1 | |
Netgenius Multilink | =6.x-2.2 | |
Netgenius Multilink | =6.x-2.3 | |
Netgenius Multilink | =6.x-2.4 | |
Netgenius Multilink | =6.x-2.5 | |
Netgenius Multilink | =6.x-2.6 | |
Drupal Drupal | ||
Netgenius Multilink | =7.x-2.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5589 has been rated as a moderate severity vulnerability due to improper node permission checks.
To fix CVE-2012-5589, upgrade to MultiLink module version 6.x-2.7 or 7.x-2.7 or later.
CVE-2012-5589 affects MultiLink module versions 6.x-2.0 through 6.x-2.6 and 7.x-2.x-dev.
Remote authenticated users with text-editing permissions can exploit CVE-2012-5589 to read arbitrary node titles.
Yes, the patch is included in the update for MultiLink module versions 6.x-2.7 and 7.x-2.7.