The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
Loading...
Loading...
Score 6.5 from GitHub Security Advisory published 2022-05-14. NVD baseline CVSS 6.5; sources differ by 0.0.
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
April 10, 2018
November 21, 2024
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-1400
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.