CVE Vulnerabilities

CVE-2010-1548

Published: May 21, 2010 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with access content privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the nodes title.

Affected Software

Name Vendor Start Version End Version
Ctools Chaos_tool_suite_project 6.x-1.0 (including) 6.x-1.0 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-alpha1 (including) 6.x-1.0-alpha1 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-alpha2 (including) 6.x-1.0-alpha2 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-alpha3 (including) 6.x-1.0-alpha3 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-beta1 (including) 6.x-1.0-beta1 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-beta2 (including) 6.x-1.0-beta2 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-beta3 (including) 6.x-1.0-beta3 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-beta4 (including) 6.x-1.0-beta4 (including)
Ctools Chaos_tool_suite_project 6.x-1.0-rc1 (including) 6.x-1.0-rc1 (including)
Ctools Chaos_tool_suite_project 6.x-1.1 (including) 6.x-1.1 (including)
Ctools Chaos_tool_suite_project 6.x-1.2 (including) 6.x-1.2 (including)
Ctools Chaos_tool_suite_project 6.x-1.3 (including) 6.x-1.3 (including)
Ctools Chaos_tool_suite_project 6.x-1.x-dev (including) 6.x-1.x-dev (including)

References