Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-10-01T00:00:00

Updated: 2024-08-06T19:26:08.437Z

Reserved: 2012-04-04T00:00:00

Link: CVE-2012-2153

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-10-01T00:55:01.133

Modified: 2013-12-13T04:59:30.167

Link: CVE-2012-2153

cve-icon Redhat

No data.