3.5
CVE-2015-5491
- EPSS 0.18%
- Veröffentlicht 18.08.2015 17:59:36
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dynamic Display Block Project ≫ Dynamic Display Block Version7.x-1.0 Updatebeta1 SwPlatformdrupal
Dynamic Display Block Project ≫ Dynamic Display Block Version7.x-1.0 Updaterc1 SwPlatformdrupal
Dynamic Display Block Project ≫ Dynamic Display Block Version7.x-1.x Updatedev SwPlatformdrupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.359 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.