CVE-2013-2122
Last modified
CVE-2013-2122 is a vulnerability of currently unknown severity. The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.. EPSS estimates a 1.56% chance of exploitation in the next 30 days.
Description
The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Quade | Edit Limit | 7.x-1.0 | — |
| Quade | Edit Limit | 7.x-1.1 | — |
| Quade | Edit Limit | 7.x-1.2 | — |
| Quade | Edit Limit | 7.x-1.x | Dev |
References
- http://secunia.com/advisories/53556Vendor Advisory
- https://drupal.org/node/2006188Vendor Advisory
- https://drupal.org/node/2007048Vendor Advisory
- http://secunia.com/advisories/53556Vendor Advisory
- https://drupal.org/node/2006188Vendor Advisory
- https://drupal.org/node/2007048Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2122?
How severe is CVE-2013-2122?
How do I fix CVE-2013-2122?
Are you affected by CVE-2013-2122?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
