Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Comment RSS模块节点标题访问未授权访问漏洞
Vulnerability Description
当一个链接添加到RSS输入端时,Drupal Comment RSS 5.x-2.2之前的5.x和6.x-2.2之前的6.x版本没有正确的执行许可,这使得远程攻击者可以通过读取该输入端,获得节点标题和可能其他敏感内容。
CVSS Information
N/A
Vulnerability Type
N/A