The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2013-07-16T18:00:00

Updated: 2017-08-28T12:57:01

Reserved: 2013-02-19T00:00:00


Link: CVE-2013-1925

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2013-07-16T18:55:01.293

Modified: 2017-08-29T01:33:12.620


Link: CVE-2013-1925

JSON object: View

cve-icon Redhat Information

No data.

CWE