CVE-2015-8754: High severity acquia mollom vulnerability
Published Jan 8, 2016
·Updated
The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors.
Affected Software
8 affected components
Acquia Mollom Drupal=6.x-2.7
Acquia Mollom Drupal=6.x-2.8
Acquia Mollom Drupal=6.x-2.9
Acquia Mollom Drupal=6.x-2.10
Acquia Mollom Drupal=6.x-2.11
Acquia Mollom Drupal=6.x-2.12
Acquia Mollom Drupal=6.x-2.13
Acquia Mollom Drupal=6.x-2.14
Remediation
Patch Available
Patch Available
Event History
Jan 8, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8754?
CVE-2015-8754 has a severity rating of moderate due to its potential to allow unauthorized modification of the mollom blacklist.
2
How do I fix CVE-2015-8754?
To fix CVE-2015-8754, update the Mollom module to version 6.x-2.15 or later.
3
What versions are affected by CVE-2015-8754?
CVE-2015-8754 affects Mollom module versions before 6.x-2.15, specifically 6.x-2.7 to 6.x-2.14.
4
What impact does CVE-2015-8754 have on Drupal sites?
CVE-2015-8754 allows remote attackers to bypass access restrictions and modify the mollom blacklist, potentially affecting spam protection.
5
Is CVE-2015-8754 specific to certain Drupal installations?
Yes, CVE-2015-8754 is specific to Drupal installations using the affected versions of the Mollom module.