Lucene search

K
cve[email protected]CVE-2015-5515
HistoryAug 18, 2015 - 6:00 p.m.

CVE-2015-5515

2015-08-1818:00:21
CWE-264
web.nvd.nist.gov
18
cve
2015
5515
vbo module
drupal
unauthorized access

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.0%

The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.

Affected configurations

NVD
Node
views_bulk_operations_projectviews_bulk_operationsMatch6.x-1.17drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch6.x-1.xdevdrupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0alpha1drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0alpha2drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0alpha3drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0beta1drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0beta2drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0beta3drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.0rc1drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.1drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.2drupal
OR
views_bulk_operations_projectviews_bulk_operationsMatch7.x-3.xdevdrupal

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.0%

Related for CVE-2015-5515