Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Token Insert Entity Project Subscribe
Filtered by product Token Insert Entity
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-8602 1 Token Insert Entity Project 1 Token Insert Entity 2015-12-18 3.5 LOW N/A
The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node.