« Volver al listado

CVE-2015-8232

Estado: ModificadaMedia (4.3)—

The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-8232",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-11-17T15:59:25.477",
  "references": [
    {
      "url": "https://www.drupal.org/node/2612812",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2613444",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2612812",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2613444",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo UC Profile 6.x-1.x en versiones anteriores a 6.x-1.3 para Drupal no comprueba adecuadamente el acceso a perfiles en ciertas circunstancias, lo que puede permitir a atacantes remotos obtener información sensible desde el perfil de usuario anonymous a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:34:11.443",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:uc_profile_project:uc_profile:6.x-1.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FE05423-C2CF-4A3A-A9BA-3DD5E54706F5"
            },
            {
              "criteria": "cpe:2.3:a:uc_profile_project:uc_profile:6.x-1.1:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59736BCB-C2B3-48E7-8559-FEEC0787AB46"
            },
            {
              "criteria": "cpe:2.3:a:uc_profile_project:uc_profile:6.x-1.1:rc2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2004E5A-B372-43C3-9486-627E119DB0B8"
            },
            {
              "criteria": "cpe:2.3:a:uc_profile_project:uc_profile:6.x-1.1:rc3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E08989E8-693C-4EAF-998C-9026403BBDF4"
            },
            {
              "criteria": "cpe:2.3:a:uc_profile_project:uc_profile:6.x-1.2:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98A7414E-39B4-4435-B381-D877110E09A9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}