AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-7306

MEDIUM · CVSS 4.9 EPSS 0.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-09-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2015-7306
Severity
MEDIUM
CVSS
4.9
EPSS
0.83%

Original NVD Description

The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.