4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
0.967 High
EPSS
Percentile
99.7%
Node Embed gives content editors an interface for selecting and embedding nodes using a WYSIWYG editor. The interface for selecting nodes is a page that had no access check, allowing users to view node titles they might not have access to. This issue only affects your site if you have unpublished nodes or use a node access module to restrict content access from some users.
CVE: CVE-2012-2722
Drupal core is not affected. If you do not use the contributed Node Embed module, there is nothing you need to do.
Install the latest version:
Also see the Node Embed project page.