LOW · 3.5

CVE-2012-4473

The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished nod...

Vulnerability Description

The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished nodes via a direct request.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Christian JohanssonRestrict Node Page View7.x-1.0
DrupalDrupal-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4473?

CVE-2012-4473 is a vulnerability with a CVSS score of 3.5 (LOW). The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished nod...

How severe is CVE-2012-4473?

CVE-2012-4473 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4473?

Check the references section above for vendor advisories and patch information. Affected products include: Christian Johansson Restrict Node Page View, Drupal Drupal.