CVE-2013-0245: Low severity drupal vulnerability
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0245?
CVE-2013-0245 has a moderate severity rating, as it allows remote authenticated users unauthorized access to read node titles and content.
How do I fix CVE-2013-0245?
To fix CVE-2013-0245, upgrade your Drupal installation to version 6.28 or 7.19 or later.
What versions of Drupal are affected by CVE-2013-0245?
CVE-2013-0245 affects Drupal versions 6.x before 6.28 and 7.x before 7.19.
Can CVE-2013-0245 be exploited by untrusted users?
No, the exploitation of CVE-2013-0245 requires remote authenticated users who have the 'access printer-friendly version' permission.
What is the impact of CVE-2013-0245 on my Drupal site?
CVE-2013-0245 can potentially expose sensitive content to unauthorized users who should not have access to specific nodes within a book outline.