AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-1973

MEDIUM · CVSS 4 EPSS 1.09%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-06-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-1973
Severity
MEDIUM
CVSS
4
EPSS
1.09%

Original NVD Description

The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified vectors.