« Volver al listado

CVE-2015-5515

Estado: ModificadaMedia (4.9)—

The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-5515",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-08-18T18:00:21.880",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/75547",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2516680",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2516688",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/75547",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2516680",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2516688",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en el módulo Views Bulk Operations (VBO) 6.x-1.x y 7.x-3.x en versiones anteriores a 7.x-3.3 para Drupal, cuando la operación bulk para cambiar Roles está habilitada, permite a usuarios remotos autenticados editar cuentas de usuario y añadir roles arbtrarios a las cuentas aprovechando el acceso a una vista de un listado de cuentas de usuario con VBO habilitado."
    }
  ],
  "lastModified": "2026-06-17T00:29:15.683",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:6.x-1.17:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3831D54-B597-4106-A709-55F537AB8522"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:6.x-1.x:dev:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39EAB0CD-29D7-422B-85C4-F0F39DD2AC5C"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52ECA9A5-43AA-4F8D-9FA1-D6462AE2FC4B"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:alpha1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAC12F28-A05A-4E04-BBC0-DFBD97AD9EAB"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:alpha2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BC5265C-A9C3-4EF1-9AC7-FB4FC2CAB817"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:alpha3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27866B2F-DFB9-4868-94ED-DA928B8AA345"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:beta1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C14EDADA-580E-4821-9755-A82B2616A20F"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:beta2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2C87F51-5063-43DE-A45D-5D5841A7AA7D"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:beta3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57A47397-28EB-4B26-9CFD-6882A02F56E1"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.0:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4459C44E-2301-4757-9E12-8B8BD2040E96"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CBDE8E2-690C-4D77-985D-D037E7644E3F"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.2:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73F66D7E-E8A1-4EE1-BE70-19E065C0B62A"
            },
            {
              "criteria": "cpe:2.3:a:views_bulk_operations_project:views_bulk_operations:7.x-3.x:dev:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EC48A38-A049-4A60-8B5D-D7A4D4FB75AE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}