CVE-2015-2559

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.
References
Link Resource
https://www.drupal.org/SA-CORE-2015-001 Vendor Advisory
http://www.debian.org/security/2015/dsa-3200 Third Party Advisory
http://www.securityfocus.com/bid/73219 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

Information

Published : 2015-03-25 07:59

Updated : 2019-02-05 10:52


NVD link : CVE-2015-2559

Mitre link : CVE-2015-2559


JSON object : View

CWE
CWE-284

Improper Access Control

Advertisement

dedicated server usa

Products Affected

debian

  • debian_linux

drupal

  • drupal