CVE-2015-7226
17.09.2015, 16:59
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.Enginsight
Vendor | Product | Version |
---|---|---|
administration_views_project | administration_views | 7.x-1.0:x |
administration_views_project | administration_views | 7.x-1.0:x |
administration_views_project | administration_views | 7.x-1.1:x |
administration_views_project | administration_views | 7.x-1.2:x |
administration_views_project | administration_views | 7.x-1.3:x |
administration_views_project | administration_views | 7.x-1.4:x |
administration_views_project | administration_views | 7.x-1.x:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References