Vulnerability Database

300,830

Total vulnerabilities in the database

CVE-2013-4273

The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was SPLIT per ADT5 due to different researcher organizations. CVE-2013-7391 was assigned for the View vector.

  • Published: Jul 19, 2014
  • Updated: Nov 9, 2025
  • CVE: CVE-2013-4273
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4
  • AV:N/AC:L/Au:S/C:P/I:N/A:N

CWEs:

Software From Fixed in
entity_api_project / entity_api 7.x-1.0-beta9 7.x-1.0-beta9.x
entity_api_project / entity_api 7.x-1.1 7.x-1.1.x
entity_api_project / entity_api 7.x-1.0-beta5 7.x-1.0-beta5.x
entity_api_project / entity_api 7.x-1.0-beta11 7.x-1.0-beta11.x
entity_api_project / entity_api 7.x-1.0-beta4 7.x-1.0-beta4.x
entity_api_project / entity_api 7.x-1.0-beta2 7.x-1.0-beta2.x
entity_api_project / entity_api 7.x-1.0-rc1 7.x-1.0-rc1.x
entity_api_project / entity_api 7.x-1.0-beta8 7.x-1.0-beta8.x
entity_api_project / entity_api 7.x-1.0-beta3 7.x-1.0-beta3.x
entity_api_project / entity_api 7.x-1.0 7.x-1.0.x
entity_api_project / entity_api 7.x-1.0-rc2 7.x-1.0-rc2.x
entity_api_project / entity_api 7.x-1.0-beta10 7.x-1.0-beta10.x
entity_api_project / entity_api 7.x-1.0-rc3 7.x-1.0-rc3.x
entity_api_project / entity_api 7.x-1.0-beta6 7.x-1.0-beta6.x
entity_api_project / entity_api 7.x-1.0-beta1 7.x-1.0-beta1.x
entity_api_project / entity_api 7.x-1.0-beta7 7.x-1.0-beta7.x