First published: Thu Nov 20 2014(Updated: )
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubercart Ubercart | =7.x-3.0 | |
Ubercart Ubercart | =7.x-3.0-alpha1 | |
Ubercart Ubercart | =7.x-3.0-alpha2 | |
Ubercart Ubercart | =7.x-3.0-alpha3 | |
Ubercart Ubercart | =7.x-3.0-beta1 | |
Ubercart Ubercart | =7.x-3.0-beta2 | |
Ubercart Ubercart | =7.x-3.0-beta3 | |
Ubercart Ubercart | =7.x-3.0-beta4 | |
Ubercart Ubercart | =7.x-3.0-rc1 | |
Ubercart Ubercart | =7.x-3.0-rc2 | |
Ubercart Ubercart | =7.x-3.0-rc3 | |
Ubercart Ubercart | =7.x-3.0-rc4 | |
Ubercart Ubercart | =7.x-3.1 | |
Ubercart Ubercart | =7.x-3.2 | |
Ubercart Ubercart | =7.x-3.3 | |
Ubercart Ubercart | =7.x-3.4 | |
Ubercart Ubercart | =7.x-3.5 | |
Ubercart Ubercart | =7.x-3.6 | |
Ubercart Ubercart | =7.x-3.7 | |
Ubercart Ubercart | =7.x-3.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9026 has a moderate severity level that potentially allows unauthorized access to sensitive user order history information.
To fix CVE-2014-9026, upgrade the Ubercart module to version 7.x-3.7 or later.
CVE-2014-9026 affects users of the Ubercart module for Drupal versions prior to 7.x-3.7 that allow authenticated users to view their order history.
CVE-2014-9026 may expose sensitive order history details to unauthorized users who have the "view own orders" permission.
Yes, if an installation is using an affected version of the Ubercart module prior to 7.x-3.7, CVE-2014-9026 remains a significant security concern.