Unrestricted Access to Default Views Configurations in Drupal Views Module

Unrestricted Access to Default Views Configurations in Drupal Views Module

CVE-2015-3379 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:N

The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

Learn more about our User Device Pen Test.