TROYANOSYVIRUS
Retour aux CVEs

CVE-2015-5515

N/A

Description

The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.

Details CVE

Score CVSS v3.1N/A
Publie8/18/2015
Derniere modification4/12/2025
Sourcenvd
Observations honeypot0

Produits affectes

views_bulk_operations_project:views_bulk_operations

Faiblesses (CWE)

CWE-264

References

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.