6
CVSSv2

CVE-2015-8761

Published: 08/01/2016 Updated: 12/01/2016
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Values module 7.x-1.x prior to 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.

Vulnerable Product Search on Vulmon Subscribe to Product

values project values 7.x-1.1

values project values 7.x-1.0