The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2013-07-16 18:55
Updated : 2017-08-29 01:33
NVD link : CVE-2013-2122
Mitre link : CVE-2013-2122
CVE.ORG link : CVE-2013-2122
JSON object : View
Products Affected
quade
- edit_limit
drupal
- drupal
CWE
CWE-264
Permissions, Privileges, and Access Controls