CVE-2015-7229
Published Sep 17, 2015
Last updated 9 years ago
Overview
- Description
- The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:twitter_project:twitter:6.x-5.0:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "35A96446-BC42-4200-A9D5-47B07551931A" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:6.x-5.1:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "EF276141-D95A-4DF5-B9F1-AB57272F4646" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:6.x-5.x:dev:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "ACD29D10-10AA-46FC-B4F5-05DB7CAE60A0" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.0:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "0E625BF0-9E89-4E9C-9F3D-95D3A6DA7EC0" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.1:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "3A57F4E9-A1EF-44BD-84EF-C3BFF9834BD9" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.2:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "192AD92A-5CCA-4D73-AA90-D02E6F6D6049" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.3:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "5E890C60-AE2C-43EA-87F5-6EAEFB61E5E0" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.4:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "596704E9-27D4-4FED-B810-83C2C477EDB6" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.5:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "10AB72A2-732E-4ADE-89E7-F4897BE38E8A" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.6:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "7E45A8CA-DE55-49F5-B1A9-A191BF8B0FEB" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.7:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "52532994-9AE9-414B-AEAA-FB9BE03E3CE1" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-5.8:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "35CB62BD-A5C3-4BA2-A6EE-0AB5AE47F042" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-6.0:alpha1:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "1A78825D-3CB2-41C5-B93C-A844B03C26E8" }, { "criteria": "cpe:2.3:a:twitter_project:twitter:7.x-6.0:alpha2:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "4173BE2C-39B9-42D7-A848-F6F4EDB20214" } ], "operator": "OR" } ] } ]