CVE-2013-7066
The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles by leveraging edit permissions to a node that references a private node.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0019 (0.2%)
Percentile: 40.4%
EPSS: 2026-05-06
Affects
entity_reference_project:entityreferenceTechnical description
The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles by leveraging edit permissions to a node that references a private node.
Published: 4/29/2014, 2:38:43 PM
Last modified: 5/6/2026, 10:30:45 PM