Description
The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.
Remediation
References
Related Vulnerabilities
WordPress Plugin Yet Another Photoblog Unspecified Vulnerability (1.10.6)
WordPress Plugin Rencontre-Dating Site Multiple Vulnerabilities (3.2.1)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2020-26185)
Java Denial of Service (DoS) Vulnerability (CVE-2019-2769)
WordPress Plugin Ceceppa Multilingua Unspecified Vulnerability (1.5.3)