Lucene search

K
cve[email protected]CVE-2013-4500
HistoryMay 13, 2014 - 3:55 p.m.

CVE-2013-4500

2014-05-1315:55:04
CWE-264
web.nvd.nist.gov
15
cve-2013-4500
drupal
quiz module
authenticated users
remote access
results deletion

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.3%

The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote authenticated users with the “view any quiz results” or “view results for own quiz” permission to delete arbitrary results via the delete option.

Affected configurations

NVD
Node
quiz_module_projectquizMatch6.x-4.0-drupal
OR
quiz_module_projectquizMatch6.x-4.0alpha1drupal
OR
quiz_module_projectquizMatch6.x-4.0alpha2drupal
OR
quiz_module_projectquizMatch6.x-4.0alpha3drupal
OR
quiz_module_projectquizMatch6.x-4.0alpha4drupal
OR
quiz_module_projectquizMatch6.x-4.0alpha5drupal
OR
quiz_module_projectquizMatch6.x-4.0beta1drupal
OR
quiz_module_projectquizMatch6.x-4.0beta2drupal
OR
quiz_module_projectquizMatch6.x-4.0beta3drupal
OR
quiz_module_projectquizMatch6.x-4.0beta4drupal
OR
quiz_module_projectquizMatch6.x-4.0beta5drupal
OR
quiz_module_projectquizMatch6.x-4.0beta6drupal
OR
quiz_module_projectquizMatch6.x-4.0beta7drupal
OR
quiz_module_projectquizMatch6.x-4.0beta8drupal
OR
quiz_module_projectquizMatch6.x-4.0devdrupal
OR
quiz_module_projectquizMatch6.x-4.0rc1drupal
OR
quiz_module_projectquizMatch6.x-4.0rc10drupal
OR
quiz_module_projectquizMatch6.x-4.0rc2drupal
OR
quiz_module_projectquizMatch6.x-4.0rc3drupal
OR
quiz_module_projectquizMatch6.x-4.0rc4drupal
OR
quiz_module_projectquizMatch6.x-4.0rc5drupal
OR
quiz_module_projectquizMatch6.x-4.0rc6drupal
OR
quiz_module_projectquizMatch6.x-4.0rc7drupal
OR
quiz_module_projectquizMatch6.x-4.0rc8drupal
OR
quiz_module_projectquizMatch6.x-4.0rc9drupal
OR
quiz_module_projectquizMatch6.x-4.1drupal
OR
quiz_module_projectquizMatch6.x-4.2drupal
OR
quiz_module_projectquizMatch6.x-4.3drupal
OR
quiz_module_projectquizMatch6.x-4.4drupal

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.3%

Related for CVE-2013-4500