Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-1590
HistoryOct 01, 2012 - 12:00 a.m.

CVE-2012-1590

2012-10-0100:00:00
ubuntu.com
ubuntu.com
14

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

69.5%

The forum list in Drupal 7.x before 7.14 does not properly check user
permissions for unpublished forum posts, which allows remote authenticated
users to obtain sensitive information such as the post title via the forum
overview page.

Bugs

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

69.5%