Lucene search

K
cve[email protected]CVE-2013-4230
HistoryAug 21, 2013 - 2:55 p.m.

CVE-2013-4230

2013-08-2114:55:07
CWE-264
web.nvd.nist.gov
21
cve-2013-4230
monster menus
drupal
webform
submission
access restriction
vulnerability
nvd

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.3%

The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the “Who can read data submitted to this webform” permission to delete arbitrary submissions via unspecified vectors.

Affected configurations

NVD
Node
monster_menus_module_projectmonster_menusMatch6.x-6.19
OR
monster_menus_module_projectmonster_menusMatch6.x-6.22
OR
monster_menus_module_projectmonster_menusMatch6.x-6.23
OR
monster_menus_module_projectmonster_menusMatch6.x-6.24
OR
monster_menus_module_projectmonster_menusMatch6.x-6.25
OR
monster_menus_module_projectmonster_menusMatch6.x-6.26
OR
monster_menus_module_projectmonster_menusMatch6.x-6.27
OR
monster_menus_module_projectmonster_menusMatch6.x-6.29
OR
monster_menus_module_projectmonster_menusMatch6.x-6.30
OR
monster_menus_module_projectmonster_menusMatch6.x-6.31
OR
monster_menus_module_projectmonster_menusMatch6.x-6.32
OR
monster_menus_module_projectmonster_menusMatch6.x-6.33
OR
monster_menus_module_projectmonster_menusMatch6.x-6.34
OR
monster_menus_module_projectmonster_menusMatch6.x-6.35
OR
monster_menus_module_projectmonster_menusMatch6.x-6.36
OR
monster_menus_module_projectmonster_menusMatch6.x-6.37
OR
monster_menus_module_projectmonster_menusMatch6.x-6.38
OR
monster_menus_module_projectmonster_menusMatch6.x-6.41
OR
monster_menus_module_projectmonster_menusMatch6.x-6.42
OR
monster_menus_module_projectmonster_menusMatch6.x-6.43
OR
monster_menus_module_projectmonster_menusMatch6.x-6.44
OR
monster_menus_module_projectmonster_menusMatch6.x-6.48
OR
monster_menus_module_projectmonster_menusMatch6.x-6.53
OR
monster_menus_module_projectmonster_menusMatch6.x-6.56
OR
monster_menus_module_projectmonster_menusMatch6.x-6.57
OR
monster_menus_module_projectmonster_menusMatch6.x-6.59
OR
monster_menus_module_projectmonster_menusMatch6.x-6.60
OR
monster_menus_module_projectmonster_menusMatch7.x-1.0
OR
monster_menus_module_projectmonster_menusMatch7.x-1.1
OR
monster_menus_module_projectmonster_menusMatch7.x-1.2
OR
monster_menus_module_projectmonster_menusMatch7.x-1.3
OR
monster_menus_module_projectmonster_menusMatch7.x-1.4
OR
monster_menus_module_projectmonster_menusMatch7.x-1.5
OR
monster_menus_module_projectmonster_menusMatch7.x-1.6
OR
monster_menus_module_projectmonster_menusMatch7.x-1.7
OR
monster_menus_module_projectmonster_menusMatch7.x-1.8
OR
monster_menus_module_projectmonster_menusMatch7.x-1.9
OR
monster_menus_module_projectmonster_menusMatch7.x-1.10
OR
monster_menus_module_projectmonster_menusMatch7.x-1.11
OR
monster_menus_module_projectmonster_menusMatch7.x-1.12
OR
monster_menus_module_projectmonster_menusMatch7.x-1.xdev
AND
drupaldrupalMatch-

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.3%

Related for CVE-2013-4230