The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspecified default views.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Invitation | Invitation_project | 7.x-2.0 (including) | 7.x-2.0 (including) |
Invitation | Invitation_project | 7.x-2.1 (including) | 7.x-2.1 (including) |