« Volver al listado

CVE-2013-7391

Estado: ModificadaMedia (5)—

The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5 due to different researcher organizations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-7391",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-07-19T18:55:01.820",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/08/22/2",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://drupal.org/node/2065197",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://drupal.org/node/2065207",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/08/22/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2065197",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2065207",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View.  NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5 due to different researcher organizations."
    },
    {
      "lang": "es",
      "value": "El módulo Entity API 7.x-1.x anterior a 7.x-1.2 para Drupal, cuando utilice (a) el campo Views o (b) los plugins de área, permite a atacantes remotos leer entidades restringidos a través de (1) el campo, (2) la cabecera o (3) el pie de un View. NOTA: este identificador fue dividido (SPLIT) del CVE-2013-4273 por ADT5 debido a organizaciones diferentes de investigadores."
    }
  ],
  "lastModified": "2026-06-17T00:01:53.187",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB8D8F33-F053-4822-8279-2185A5943C08",
              "versionEndIncluding": "7.x-1.1"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "433019DB-4AA8-47A2-8F40-DF942F87177F"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CD17D74-DF27-41F1-850A-8F9FEC887F86"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta10:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFAE7C60-0497-4A75-A2D9-2BA89CB42F0E"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta11:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5CE0E97-770A-4239-A021-F3A3FB242EA4"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "877CD3BE-0F6F-4343-A752-7698ACFFCD1B"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B592B392-1FAE-4BEF-99DC-7C5AB84E15C3"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta4:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83E7DE0A-D756-459B-99CE-621026A29FB6"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta5:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E349B3F-8AD3-4E1C-B7BE-BCF5552C4BBC"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta6:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B38D7DCA-F83C-4D0F-B545-062B914FBE5B"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta7:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8E2C960-9C71-4546-82AE-AEB5A83377CD"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta8:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B194AA3-0869-4D2C-AC6D-AB6BB2C65091"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:beta9:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB91C2BC-6188-4679-BDA9-F3B3D2DB395A"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A2F77EA-EE98-4399-A9B8-45104A94ECF9"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:rc2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "798ACA1B-1E81-48EA-ABED-9E0E18EE50EF"
            },
            {
              "criteria": "cpe:2.3:a:entity_api_project:entity_api:7.x-1.0:rc3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6768BCC0-9F2C-45A8-9ADC-B6D7A650DC35"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}