Lucene search

K
cve[email protected]CVE-2012-5543
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-5543

2022-10-0316:15:31
CWE-264
web.nvd.nist.gov
21
cve-2012-5543
feeds module
drupal
remote attackers
arbitrary nodes
permission issue
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.2%

The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node’s author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed.

Affected configurations

NVD
Node
feeds_projectfeedsMatch7.x-2.0alpha1
OR
feeds_projectfeedsMatch7.x-2.0alpha2
OR
feeds_projectfeedsMatch7.x-2.0alpha3
OR
feeds_projectfeedsMatch7.x-2.0alpha4
OR
feeds_projectfeedsMatch7.x-2.0alpha5
OR
feeds_projectfeedsMatch7.x-2.x
AND
drupaldrupalMatch-

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.2%

Related for CVE-2012-5543