|
|
| |
|
| |
drupal7: restriction bypass
| Package(s): | drupal7 |
CVE #(s): | CVE-2011-2687
|
| Created: | July 18, 2011 |
Updated: | July 20, 2011 |
| Description: |
From the Drupal advisory:
Listings showing nodes but not JOINing the node table show all nodes regardless of restrictions imposed by the node_access system. In core, this affects the taxonomy and the forum subsystem. |
| Alerts: |
|
( Log in to post comments)
|
|
|