The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain user passwords via unspecified vectors.
References
Configurations
History
21 Nov 2024, 02:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2015/07/04/4 - | |
References | () http://www.securityfocus.com/bid/74755 - | |
References | () https://www.drupal.org/node/2492205 - Patch, Vendor Advisory |
Information
Published : 2015-08-18 17:59
Updated : 2024-11-21 02:33
NVD link : CVE-2015-5496
Mitre link : CVE-2015-5496
CVE.ORG link : CVE-2015-5496
JSON object : View
Products Affected
pass2pdf_project
- pass2pdf
CWE
CWE-264
Permissions, Privileges, and Access Controls