Back to search
CVE-2015-5515
Published: Aug 18, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.drupal.org/node/2516680
x_refsource_CONFIRM
75547
vdb-entry
x_refsource_BID
https://www.drupal.org/node/2516688
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now