5.5
CVE-2014-9023
- EPSS 0.16%
- Veröffentlicht 20.11.2014 17:50:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authenticated users to read and modify authentication tokens by leveraging the "access administration pages" Drupal permission.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Twilio Project ≫ Twilio Version7.x-1.1 SwPlatformdrupal
Twilio Project ≫ Twilio Version7.x-1.2 SwPlatformdrupal
Twilio Project ≫ Twilio Version7.x-1.4 SwPlatformdrupal
Twilio Project ≫ Twilio Version7.x-1.5 SwPlatformdrupal
Twilio Project ≫ Twilio Version7.x-1.6 SwPlatformdrupal
Twilio Project ≫ Twilio Version7.x-1.8 SwPlatformdrupal
Twilio Project ≫ Twilio Version7.x-1.9 SwPlatformdrupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.33 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|