Lucene search

K
cvelistMitreCVELIST:CVE-2015-7229
HistorySep 17, 2015 - 4:00 p.m.

CVE-2015-7229

2015-09-1716:00:00
mitre
www.cve.org
3
twitter module
drupal
remote authenticated users
access permissions
post tweets
arbitrary accounts.

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

49.7%

The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) โ€œpost to twitterโ€ permission or change the options for arbitrary attached accounts by leveraging the (2) โ€œadd twitter accountsโ€ or (3) โ€œadd authenticated twitter accountsโ€ permission.

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

49.7%

Related for CVELIST:CVE-2015-7229