CVE-2015-7226 Information
Feb 14, 2021
cve
Description
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property which allows remote attackers to obtain sensitive information via vectors related to the access handler.
Reference
http://cgit.drupalcode.org/admin_views/commit/?id=44098bb http://www.securityfocus.com/bid/75697 https://www.drupal.org/node/2529366 https://www.drupal.org/node/2529378
Share on: