J-Security Center

Title: Drupal Comment RSS Module Node Title Access Unauthorized Access Vulnerability

Severity: MODERATE

Description:

Comment RSS is a module for the Drupal content manager.

The module is prone to an unauthorized-access vulnerability that occurs when adding a link to an RSS feed to the node title. When adding a link, the application fails to enforce certain access permissions.

Attackers can exploit this issue to obtain sensitive information.

Affected Products:

  • Drupal Comment RSS 5.x-2.1
  • Drupal Comment RSS 6.X-2.1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.