security.nuyts.tech
CVE-2012-4500 – NuytsTech Security
The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node