Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Project 事件跟踪模块 访问控制绕过漏洞
Vulnerability Description
Drupal Project事件跟踪模块 4.7.x-1.3之前版本和4.7.x-2.3之前的4.7.x-2.*版本以及5.x-0.2-beta之前的5版本允许拥有"访问项目事件"许可的远程认证用户借助一个包含有修改过的节点标识符的URL,读取私人节点的内容。
CVSS Information
N/A
Vulnerability Type
N/A