CVE-2015-8602

The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:token_insert_entity_project:token_insert_entity:7.x-1.0:*:*:*:*:drupal:*:*

History

No history.

Information

Published : 2015-12-17 19:59

Updated : 2024-02-28 15:21


NVD link : CVE-2015-8602

Mitre link : CVE-2015-8602

CVE.ORG link : CVE-2015-8602


JSON object : View

Products Affected

token_insert_entity_project

  • token_insert_entity
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor