The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain sensitive information via a crafted link.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/68861 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/94870 - | |
References | () https://www.drupal.org/node/2308503 - Vendor Advisory |
Information
Published : 2014-08-06 18:55
Updated : 2024-11-21 02:11
NVD link : CVE-2014-5179
Mitre link : CVE-2014-5179
CVE.ORG link : CVE-2014-5179
JSON object : View
Products Affected
freelinking_project
- freelinking
freelinking_for_case_tracker_project
- freelinking_for_case_tracker
CWE
CWE-264
Permissions, Privileges, and Access Controls