7.5
CVSSv2

CVE-2015-5502

Published: 18/08/2015 Updated: 28/11/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Storage API module 7.x-1.x prior to 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote malicious users to have unspecified impact via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

storage api project storage api 7.x-1.5

storage api project storage api 7.x-1.6

storage api project storage api 7.x-1.1

storage api project storage api 7.x-1.2

storage api project storage api 7.x-1.0

storage api project storage api 7.x-1.7

storage api project storage api 7.x-1.3

storage api project storage api 7.x-1.4