First published: Fri Jan 08 2016(Updated: )
The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acquia Mollom | =6.x-2.7 | |
Acquia Mollom | =6.x-2.8 | |
Acquia Mollom | =6.x-2.9 | |
Acquia Mollom | =6.x-2.10 | |
Acquia Mollom | =6.x-2.11 | |
Acquia Mollom | =6.x-2.12 | |
Acquia Mollom | =6.x-2.13 | |
Acquia Mollom | =6.x-2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8754 has a severity rating of moderate due to its potential to allow unauthorized modification of the mollom blacklist.
To fix CVE-2015-8754, update the Mollom module to version 6.x-2.15 or later.
CVE-2015-8754 affects Mollom module versions before 6.x-2.15, specifically 6.x-2.7 to 6.x-2.14.
CVE-2015-8754 allows remote attackers to bypass access restrictions and modify the mollom blacklist, potentially affecting spam protection.
Yes, CVE-2015-8754 is specific to Drupal installations using the affected versions of the Mollom module.