4
CVSSv2

CVE-2014-9026

Published: 20/11/2014 Updated: 21/11/2014
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Ubercart module 7.x-3.x prior to 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

ubercart ubercart 7.x-3.0

ubercart ubercart 7.x-3.6

ubercart ubercart 7.x-3.7

ubercart ubercart 7.x-3.3

ubercart ubercart 7.x-3.5

ubercart ubercart 7.x-3.1

ubercart ubercart 7.x-3.x-dev

ubercart ubercart 7.x-3.2

ubercart ubercart 7.x-3.4