CVE-2013-4273: Medium severity entity api for drupal vulnerability
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was SPLIT per ADT5 due to different researcher organizations. CVE-2013-7391 was assigned for the View vector.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4273?
CVE-2013-4273 is classified as a moderate severity vulnerability due to improper access restrictions.
How do I fix CVE-2013-4273?
To fix CVE-2013-4273, upgrade the Entity API module to version 7.x-1.2 or later.
Which versions of Entity API for Drupal are affected by CVE-2013-4273?
CVE-2013-4273 affects versions 7.x-1.0 to 7.x-1.1 of the Entity API module.
What can attackers do by exploiting CVE-2013-4273?
By exploiting CVE-2013-4273, attackers can read node comments that they should not have access to.
Is CVE-2013-4273 a remote vulnerability?
Yes, CVE-2013-4273 is a remote vulnerability that can be exploited by authenticated users.