CVE-2015-8601
17.12.2015, 19:59
The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors.Enginsight
Vendor | Product | Version |
---|---|---|
chat_room_project | chat_room | 7.x-2.0:x |
chat_room_project | chat_room | 7.x-2.1:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration