4

CVE-2014-9026

The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ubercart ≫ Ubercart Version 7.x-3.0 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha1 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha2 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha3 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta1 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta2 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta3 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta4 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc1 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc2 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc3 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc4 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.1 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.2 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.3 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.4 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.5 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.6 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.7 SwPlatform drupal
Ubercart ≫ Ubercart Version 7.x-3.x-dev SwPlatform drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.94% 0.562
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.drupal.org/node/2336109
Patch
https://www.drupal.org/node/2336259
Vendor Advisory