TROYANOSYVIRUS
Back to CVEs

CVE-2015-5515

N/A

Description

The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.

CVE Details

CVSS v3.1 ScoreN/A
Published8/18/2015
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

views_bulk_operations_project:views_bulk_operations

Weaknesses (CWE)

CWE-264

References

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.