CyberRota
Live Feed
Return to register
Case File

CVE-2012-2153

MEDIUM · CVSS 4 EPSS 1.88%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-10-01 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-2153
Severity
MEDIUM
CVSS
4
EPSS
1.88%

Original Filing — NVD Description

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.