Vulnerability Details CVE-2015-5498
The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not check the view permission for the shipments overview (admin/shipwire/shipments), which allows remote attackers to obtain sensitive information via a request to the page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2015-5498
-
cpe:2.3:a:shipwire_api_project:shipwire_api:7.x-1.0
-
cpe:2.3:a:shipwire_api_project:shipwire_api:7.x-1.01
-
cpe:2.3:a:shipwire_api_project:shipwire_api:7.x-1.02