CVE-2011-2687

EPSS 0.77%

Drupal Access Control Bypass

發布日:2022/5/17修改日:2024/1/19

描述

Drupal 7.x before 7.3 allows remote attackers to bypass intended `node_access` restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

受影響套件(1)

參考連結(9)