CVE-2015-7306

The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drupaldise:cms_updater:7.x-1.2:*:*:*:*:drupal:*:*
cpe:2.3:a:drupaldise:cms_updater:7.x-1.1:*:*:*:*:drupal:*:*
cpe:2.3:a:drupaldise:cms_updater:7.x-1.0:*:*:*:*:drupal:*:*

Information

Published : 2015-09-21 12:59

Updated : 2015-09-22 20:03


NVD link : CVE-2015-7306

Mitre link : CVE-2015-7306


JSON object : View

CWE
CWE-284

Improper Access Control

Advertisement

dedicated server usa

Products Affected

drupaldise

  • cms_updater