VulnerabilityModified
CVE-2015-7226
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the…
MEDIUM 5.0EPSS 2.09%
Does this matter?
Lower severity and a low EPSS score (2.09%). Track it; it rarely justifies an emergency change on its own.
Description
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.09% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- administration views project/administration views
- Source
- cve@mitre.org
References
- http://cgit.drupalcode.org/admin_views/commit/?id=44098bb
- http://www.securityfocus.com/bid/75697
- https://www.drupal.org/node/2529366Patch
- https://www.drupal.org/node/2529378Patch, Vendor Advisory
- http://cgit.drupalcode.org/admin_views/commit/?id=44098bb
- http://www.securityfocus.com/bid/75697
- https://www.drupal.org/node/2529366Patch
- https://www.drupal.org/node/2529378Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.