First published: Thu Sep 17 2015(Updated: )
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=6.x-5.0 | ||
=6.x-5.1 | ||
=6.x-5.x-dev | ||
=7.x-5.0 | ||
=7.x-5.1 | ||
=7.x-5.2 | ||
=7.x-5.3 | ||
=7.x-5.4 | ||
=7.x-5.5 | ||
=7.x-5.6 | ||
=7.x-5.7 | ||
=7.x-5.8 | ||
=7.x-6.0-alpha1 | ||
=7.x-6.0-alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7229 has a moderate severity rating due to improper access permissions allowing exploitation.
To fix CVE-2015-7229, update the Twitter module for Drupal to version 6.x-5.2 or 7.x-5.9 or later.
CVE-2015-7229 affects the Twitter module versions 6.x-5.0 to 6.x-5.1 and 7.x-5.0 to 7.x-5.8.
Attackers can post tweets to arbitrary accounts if they have privileged access due to the vulnerability in access permissions.
Yes, CVE-2015-7229 allows remote authenticated users to exploit it under certain conditions.