« Back to list

CVE-2015-5491

Status: ModifiedLow (3.5)—

The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2015-5491",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-08-18T17:59:36.880",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2484157",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2504965",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2484157",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2504965",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the \"administer ddblock\" permission."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en el módulo Dynamic display block module 7.x-1.x en versiones anteriores a 7.x-1.1 para Drupal, permite a usuarios remotos autenticados eludir las restricciones destinadas al acceso y leer títulos sensibles aprovechando el permiso 'administer ddblock'."
    }
  ],
  "lastModified": "2026-06-17T00:29:13.060",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dynamic_display_block_project:dynamic_display_block:7.x-1.0:beta1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E476E22-75CC-47F4-BB73-1FADB097D385"
            },
            {
              "criteria": "cpe:2.3:a:dynamic_display_block_project:dynamic_display_block:7.x-1.0:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7C883C8-F376-4848-85B2-AE73F4FEE57F"
            },
            {
              "criteria": "cpe:2.3:a:dynamic_display_block_project:dynamic_display_block:7.x-1.x:dev:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C06148B-ED40-44B3-B740-DA6A5D35F500"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}