CVE-2015-8602

The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:token_insert_entity_project:token_insert_entity:7.x-1.0:*:*:*:*:drupal:*:*

Information

Published : 2015-12-17 11:59

Updated : 2015-12-18 10:45


NVD link : CVE-2015-8602

Mitre link : CVE-2015-8602


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

token_insert_entity_project

  • token_insert_entity