3.5

CVE-2015-5491

The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dynamic Display Block ProjectDynamic Display Block Version7.x-1.0 Updatebeta1 SwPlatformdrupal
Dynamic Display Block ProjectDynamic Display Block Version7.x-1.0 Updaterc1 SwPlatformdrupal
Dynamic Display Block ProjectDynamic Display Block Version7.x-1.x Updatedev SwPlatformdrupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.01% 0.586
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.openwall.com/lists/oss-security/2015/07/04/4
https://www.drupal.org/node/2484157
Patch
Vendor Advisory
https://www.drupal.org/node/2504965
Patch