Required CVE Record Information
Description
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- http://drupal.org/node/1289294 x_transferred
- openwall.com: [oss-security] 20121128 Re: CVE request for Drupal contributed modules mailing-listx_transferred
- http://drupal.org/node/1853244 x_transferred
- http://drupal.org/node/1289292 x_transferred