Remote Code Execution in Project Issue Tracking Module for Drupal
CVE-2007-1368

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
9 March 2007

What is CVE-2007-1368?

The Project issue tracking module for Drupal allows remote authenticated users with the 'access project issues' permission to exploit a security bypass. By altering a node identifier in the URL, these users can access the contents of private nodes that should otherwise remain confidential. This vulnerability highlights the importance of proper access controls and validation mechanisms to prevent unauthorized data exposure, underscoring the need for timely updates and security best practices.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2007-1368 : Remote Code Execution in Project Issue Tracking Module for Drupal