What the vulnerability does
01Description
Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0.
CVSS base score
What the vulnerability does
Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0.
Explanation of Vulnerability in Simple Terms
The Unpublished Node Permissions module for Drupal contains an authorization flaw that allows users to access or modify unpublished nodes beyond their intended permissions. The vulnerability stems from incorrect permission checks when handling unpublished content. Administrators should update to version 1.7.0 or later to resolve this issue.
What an attacker can do
Access or modify unpublished nodes that should be restricted to specific users.
Potential impact on your site
Unpublished content may be exposed to unauthorized users, risking data leakage or unintended modifications.
Conditions required to exploit
User must have some level of access to the Drupal site; specific privilege requirements unknown.
Key dates
External resources
Related vulnerabilities