// For flags

CVE-2015-7226

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.

Vulnerabilidad en el módulo Administration Views 7.x-1.x en versiones anteriores a 7.x-1.5 para Drupal, comprueba los permisos de acceso basándose en la ruta del router desde view en lugar de la propiedad display, lo que permite a atacantes remotos obtener información sensible a través de vectores relacionados con el manejo de accesos.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-09-17 CVE Reserved
  • 2015-09-17 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Administration Views Project
Search vendor "Administration Views Project"
Administration Views
Search vendor "Administration Views Project" for product "Administration Views"
7.x-1.0
Search vendor "Administration Views Project" for product "Administration Views" and version "7.x-1.0"
drupal
Affected
Administration Views Project
Search vendor "Administration Views Project"
Administration Views
Search vendor "Administration Views Project" for product "Administration Views"
7.x-1.0
Search vendor "Administration Views Project" for product "Administration Views" and version "7.x-1.0"
rc1, drupal
Affected
Administration Views Project
Search vendor "Administration Views Project"
Administration Views
Search vendor "Administration Views Project" for product "Administration Views"
7.x-1.1
Search vendor "Administration Views Project" for product "Administration Views" and version "7.x-1.1"
drupal
Affected
Administration Views Project
Search vendor "Administration Views Project"
Administration Views
Search vendor "Administration Views Project" for product "Administration Views"
7.x-1.2
Search vendor "Administration Views Project" for product "Administration Views" and version "7.x-1.2"
drupal
Affected
Administration Views Project
Search vendor "Administration Views Project"
Administration Views
Search vendor "Administration Views Project" for product "Administration Views"
7.x-1.3
Search vendor "Administration Views Project" for product "Administration Views" and version "7.x-1.3"
drupal
Affected
Administration Views Project
Search vendor "Administration Views Project"
Administration Views
Search vendor "Administration Views Project" for product "Administration Views"
7.x-1.4
Search vendor "Administration Views Project" for product "Administration Views" and version "7.x-1.4"
drupal
Affected
Administration Views Project
Search vendor "Administration Views Project"
Administration Views
Search vendor "Administration Views Project" for product "Administration Views"
7.x-1.x
Search vendor "Administration Views Project" for product "Administration Views" and version "7.x-1.x"
dev, drupal
Affected