CVE-2015-7881: Low severity colorbox vulnerability
The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors, possibly related to a link in a comment.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7881?
CVE-2015-7881 has a medium severity rating due to the potential for unauthorized content addition by authenticated users.
How do I fix CVE-2015-7881?
To fix CVE-2015-7881, update the Colorbox module to version 7.x-2.10 or later.
Who is affected by CVE-2015-7881?
CVE-2015-7881 affects Drupal users with the Colorbox module versions 7.x-2.0 through 7.x-2.9.
What kind of access does CVE-2015-7881 allow attackers?
CVE-2015-7881 allows attackers to bypass access restrictions and add unexpected content to Colorbox.
Is there a workaround for CVE-2015-7881?
There are no specific workarounds documented for CVE-2015-7881; updating the module is the recommended action.