High
CVSS 7.5
Overview
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access res...
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
This vulnerability is rated 🟠 HIGH.
Recommended actions: