CVE Database
/

CVE-2010-1548

Back to search

CVE-2010-1548

Published: May 21, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.

VendorProductVersions

n/a

n/a

affected
n/a

References

39884
third-party-advisory
x_refsource_SECUNIA
40285
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now