« Volver al listado

CVE-2013-1925

Estado: ModificadaBaja (3.5)—

The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1925",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-07-16T18:55:01.293",
  "references": [
    {
      "url": "http://osvdb.org/91986",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/Apr/8",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1960406",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1960424",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83254",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://osvdb.org/91986",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/121072/Drupal-Chaos-Tool-Suite-7.x-Access-Bypass.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/Apr/8",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1960406",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1960424",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83254",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the \"access content\" permission to read restricted node titles via an autocomplete list."
    },
    {
      "lang": "es",
      "value": "El módulo Chaos Tool Suite (ctools) 7.x-1.x anterior a 7.x-1.3 para Drupal no restringe adecuadamente el acceso a los nodos, lo que permite a usuarios autenticados remotamente con permisos de \"acceso al contenido\" la lectura de nodos restringidos a través de una lista que se autocompleta."
    }
  ],
  "lastModified": "2026-06-16T23:52:24.733",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FA4E46D-F7D9-448D-B971-D8EE786EB3AC"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03BCA1E8-4733-4653-BA48-EEB373DFE218"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A481BBC-B7DE-4AB7-A582-85E02ADFCAEE"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00DBF5CE-D194-4446-80C8-C332AD02E50E"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha4:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16B9EAD7-E9A4-451D-9A23-E9372C239322"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:beta1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAD3327C-8619-4A96-B9C9-FFB4F374492C"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62E855A8-381E-471B-AD3F-811DA35DAAE3"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:rc2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5055F95-FEC4-4C14-8DD6-AD535FBCD401"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFA33F20-D932-42F3-84B0-9E55645D64D6"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.2:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F56B3706-6AF5-42C9-A565-882AE03ADA9D"
            },
            {
              "criteria": "cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.x:dev:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6792E424-EA0A-4341-91E6-9C14446B6FCF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}