This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Autocomplete Widgets Project First view 2014-06-09
Product Autocomplete Widgets Last view 2014-06-09
Version 7.x-1.x Type Application
Update beta1  
Edition -  
Language *  
Sofware Edition -  
Target Software drupal  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:autocomplete_widgets_project:autocomplete_widgets

Activity : Overall

Related : CVE

  Date Alert Description
4 2014-06-09 CVE-2013-1973

The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified vectors.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-264 Permissions, Privileges, and Access Controls