First published: Thu Sep 17 2015(Updated: )
The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Formidable Pro2pdf | =7.x-1.0 | |
Formidable Pro2pdf | =7.x-1.0-beta2 | |
Formidable Pro2pdf | =7.x-1.1 | |
Formidable Pro2pdf | =7.x-1.2 | |
Formidable Pro2pdf | =7.x-1.3 | |
Formidable Pro2pdf | =7.x-1.4 | |
Formidable Pro2pdf | =7.x-1.5 | |
Formidable Pro2pdf | =7.x-1.6 | |
Formidable Pro2pdf | =7.x-1.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7227 has been classified as a moderate severity vulnerability.
To fix CVE-2015-7227, upgrade the Fieldable Panels Panes module to version 7.x-1.7 or later.
CVE-2015-7227 affects remote authenticated users who have permission to edit panels in Drupal installations with versions prior to 7.x-1.7.
CVE-2015-7227 allows an attacker to potentially edit Fieldable Panels Panes entities without having appropriate permissions.
CVE-2015-7227 is considered a remote vulnerability as it can be exploited by authenticated users from a remote location.