5
CVE-2015-8095
- EPSS 0.25%
- Veröffentlicht 09.11.2015 16:59:12
- Zuletzt bearbeitet 27.08.2025 15:51:13
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL pattern.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Monster Menus Project ≫ Monster Menus Version7.x-1.0
Monster Menus Project ≫ Monster Menus Version7.x-1.1
Monster Menus Project ≫ Monster Menus Version7.x-1.2
Monster Menus Project ≫ Monster Menus Version7.x-1.3
Monster Menus Project ≫ Monster Menus Version7.x-1.4
Monster Menus Project ≫ Monster Menus Version7.x-1.5
Monster Menus Project ≫ Monster Menus Version7.x-1.6
Monster Menus Project ≫ Monster Menus Version7.x-1.7
Monster Menus Project ≫ Monster Menus Version7.x-1.8
Monster Menus Project ≫ Monster Menus Version7.x-1.9
Monster Menus Project ≫ Monster Menus Version7.x-1.10
Monster Menus Project ≫ Monster Menus Version7.x-1.11
Monster Menus Project ≫ Monster Menus Version7.x-1.12
Monster Menus Project ≫ Monster Menus Version7.x-1.13
Monster Menus Project ≫ Monster Menus Version7.x-1.14
Monster Menus Project ≫ Monster Menus Version7.x-1.15
Monster Menus Project ≫ Monster Menus Version7.x-1.16
Monster Menus Project ≫ Monster Menus Version7.x-1.17
Monster Menus Project ≫ Monster Menus Version7.x-1.18
Monster Menus Project ≫ Monster Menus Version7.x-1.19
Monster Menus Project ≫ Monster Menus Version7.x-1.20
Monster Menus Project ≫ Monster Menus Version7.x-1.21
Monster Menus Project ≫ Monster Menus Version7.x-1.22
Monster Menus Project ≫ Monster Menus Version7.x-1.23
Monster Menus Project ≫ Monster Menus Version7.x-1.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.455 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.