« Volver al listado

CVE-2013-2122

Estado: ModificadaMedia (5)—

The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-2122",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-07-16T18:55:01.340",
  "references": [
    {
      "url": "http://osvdb.org/93725",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/May/208",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/53556",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/05/29/9",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/60209",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2006188",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2007048",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/84630",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://osvdb.org/93725",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/May/208",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/53556",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/05/29/9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/60209",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2006188",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2007048",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/84630",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the \"edit comments\" permission to edit arbitrary comments of other users via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo Edit Limit v7.x-1.x anterior a v7.x-1.3 para Drupal no restringe adecuadamente el acceso a los comentarios, permitiendo a usuarios remotos autenticados con los permisos \"edit comments\" editar los comentarios arbitrarias de otros usuarios a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:52:47.243",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38BC0267-91AE-40F6-9B95-793DA675956D"
            },
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB6A1161-CF99-4421-AD73-7BAB6AA3B60A"
            },
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B26B8F8-D6B9-466D-BDF0-55A104BF1614"
            },
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C72A8F6E-F949-47FB-AF6A-FF42B18FCDB7"
            },
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87779D72-190B-4A38-8B1D-0507965F616B"
            },
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEB23F27-D97C-49EA-99C9-C8010C1B2D00"
            },
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4A8F886-A3EC-4075-A04C-BB8AD9E4F678"
            },
            {
              "criteria": "cpe:2.3:a:quade:edit_limit:7.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFDBDD60-27FC-4664-A25E-D0BABF1E9E37"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}