CVE-2015-4375: Infoleak
The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the impact of CVE-2015-4375?
CVE-2015-4375 allows remote attackers to access sensitive node titles via an autocomplete search on custom entities.
Which versions of Ctools are affected by CVE-2015-4375?
CVE-2015-4375 affects all versions of Chaos Tool Suite (Ctools) from 7.x-1.0 to 7.x-1.6.
How do I fix CVE-2015-4375?
To fix CVE-2015-4375, upgrade to Chaos Tool Suite (Ctools) version 7.x-1.7 or later.
Who can be affected by CVE-2015-4375?
All Drupal installations using affected versions of Ctools can be exploited if they allow unauthorized access to autocomplete functionality.
What kind of vulnerability is CVE-2015-4375 classified as?
CVE-2015-4375 is classified as an information disclosure vulnerability due to the exposure of sensitive information.