CVE-2013-7063
Publication date 29 April 2014
Last updated 24 July 2024
Ubuntu priority
Description
The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspecified default views.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| drupal6 | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| drupal7 | ||
| 16.04 LTS xenial | 
                              
                               
                                Not affected 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 14.04 LTS trusty | 
                              
                               
                                Not affected 
                                
                               
                             |      
                          
                            
                          
                        
                      |
Notes
leosilva
"Drupal core is not affected. If you do not use the contributed Invitation module, there is nothing you need to do." "Solution: If you use the Invitation module for Drupal 7.x, you should disable the module. There is no release with a fix."