Lucene search

K
cve[email protected]CVE-2012-4488
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-4488

2022-10-0316:15:35
CWE-264
web.nvd.nist.gov
22
cve-2012-4488
drupal
location module
access permissions
remote attackers
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.5%

The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows remote attackers to read node or user results via the location search page.

Affected configurations

NVD
Node
location_module_projectlocationMatch6.x-3.0
OR
location_module_projectlocationMatch6.x-3.0rc1
OR
location_module_projectlocationMatch6.x-3.0rc2
OR
location_module_projectlocationMatch6.x-3.0test3
OR
location_module_projectlocationMatch6.x-3.1
OR
location_module_projectlocationMatch6.x-3.1rc1
OR
location_module_projectlocationMatch6.x-3.xdev
OR
location_module_projectlocationMatch7.x-1.0beta1
OR
location_module_projectlocationMatch7.x-3.xdev
OR
location_module_projectlocationMatch7.x-4.xdev
OR
location_module_projectlocationMatch7.x-5.xdev
AND
drupaldrupalMatch-

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.5%

Related for CVE-2012-4488