CVE-2011-2687

EPSS 0.77%

Drupal Access Control Bypass

Published: 5/17/2022Modified: 1/19/2024

Description

Drupal 7.x before 7.3 allows remote attackers to bypass intended `node_access` restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

Affected packages (1)

References (9)