CVE-2013-5965: Medium severity adcisolutions node view permissions vulnerability
Published Sep 30, 2013
·Updated
The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hookqueryalter function, which might allow remote attackers to obtain sensitive information by reading a node listing.
Affected Software
3 affected components
Adcisolutions Node View Permissions<=7.x-1.1
Adcisolutions Node View Permissions=7.x-1.0
Drupal Drupal
Remediation
Patch Available
Patch Available
Event History
Sep 30, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5965?
CVE-2013-5965 has a medium severity rating as it allows remote attackers to access potentially sensitive information.
2
How do I fix CVE-2013-5965?
To fix CVE-2013-5965, update the Adcisolutions Node View Permissions module to version 7.x-1.2 or later.
3
Which versions of the Node View Permissions module are affected by CVE-2013-5965?
The affected versions are 7.x-1.0 and 7.x-1.1 of the Node View Permissions module.
4
What does CVE-2013-5965 vulnerability affect?
CVE-2013-5965 affects the Node View Permissions module for Drupal, specifically versions prior to 7.x-1.2.
5
Can CVE-2013-5965 cause data exposure?
Yes, CVE-2013-5965 can lead to data exposure by allowing unauthorized users to read node listings.