LOW · 3.5

CVE-2013-1925

The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read rest...

Vulnerability Description

The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Chaos Tool Suite ProjectCtools7.x-1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-1925?

CVE-2013-1925 is a vulnerability with a CVSS score of 3.5 (LOW). The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read rest...

How severe is CVE-2013-1925?

CVE-2013-1925 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1925?

Check the references section above for vendor advisories and patch information. Affected products include: Chaos Tool Suite Project Ctools.