CVE-2014-9026

EUVD-2014-8854
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.0:x
ubercartubercart
7.x-3.1:x
ubercartubercart
7.x-3.2:x
ubercartubercart
7.x-3.3:x
ubercartubercart
7.x-3.4:x
ubercartubercart
7.x-3.5:x
ubercartubercart
7.x-3.6:x
ubercartubercart
7.x-3.7:x
ubercartubercart
7.x-3.x-dev:x
𝑥
= Vulnerable software versions
Common Weakness Enumeration