First published: Tue Aug 18 2015(Updated: )
The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Storage API | =7.x-1.0 | |
Storage API | =7.x-1.1 | |
Storage API | =7.x-1.2 | |
Storage API | =7.x-1.3 | |
Storage API | =7.x-1.4 | |
Storage API | =7.x-1.5 | |
Storage API | =7.x-1.6 | |
Storage API | =7.x-1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5502 is considered a moderate severity vulnerability due to its potential impact on access controls.
To fix CVE-2015-5502, update the Storage API module to version 7.x-1.8 or later.
CVE-2015-5502 affects Storage API module versions prior to 7.x-1.8, including versions 7.x-1.0 through 7.x-1.7.
CVE-2015-5502 may allow remote attackers to exploit improper access restrictions on Storage API fields attached to non-node entities.
As of now, there are no publicly disclosed exploits for CVE-2015-5502, but the vulnerability could be exploited by unauthorized users.