Vulnerability Details CVE-2015-7306
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 53.4%
CVSS Severity
CVSS v2 Score 4.9
Products affected by CVE-2015-7306
-
cpe:2.3:a:drupaldise:cms_updater:7.x-1.0
-
cpe:2.3:a:drupaldise:cms_updater:7.x-1.1
-
cpe:2.3:a:drupaldise:cms_updater:7.x-1.2