drupal7: restriction bypass
| Package(s): | drupal7 | CVE #(s): | CVE-2011-2687 | ||||||||
| Created: | July 18, 2011 | Updated: | July 20, 2011 | ||||||||
| Description: | From the Drupal advisory:
Listings showing nodes but not JOINing the node table show all nodes regardless of restrictions imposed by the node_access system. In core, this affects the taxonomy and the forum subsystem. | ||||||||||
| Alerts: |
| ||||||||||
