Loading...
Loading...
The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.
August 28, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-2123
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.