CVE-2013-0245

Drupal 6.x < 6.28 and 7.x < 7.19 - Authenticated Access Bypass via Book Module Printer-Friendly Version

Title source: llm
STIX 2.1

Description

The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.

References (8)

Core 8
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q1/211
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/89305
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2776
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/81380
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jan/120
Patch, Vendor Advisory x_refsource_confirm
https://drupal.org/SA-CORE-2013-001
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51717

Scores

EPSS 0.0041
EPSS Percentile 61.6%

Details

CWE
CWE-264
Status published
Products (29)
drupal/drupal 6.0 (10 CPE variants)
drupal/drupal 6.1
drupal/drupal 6.2
drupal/drupal 6.3
drupal/drupal 6.4
drupal/drupal 6.5
drupal/drupal 6.6
drupal/drupal 6.7
drupal/drupal 6.8
drupal/drupal 6.9
... and 19 more
Published Jul 16, 2013
Tracked Since Feb 18, 2026