The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2015/07/04/4 | |
| https://www.drupal.org/node/2484157 | Patch Vendor Advisory | 
| https://www.drupal.org/node/2504965 | Patch | 
| http://www.openwall.com/lists/oss-security/2015/07/04/4 | |
| https://www.drupal.org/node/2484157 | Patch Vendor Advisory | 
| https://www.drupal.org/node/2504965 | Patch | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 02:33
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.openwall.com/lists/oss-security/2015/07/04/4 - | |
| References | () https://www.drupal.org/node/2484157 - Patch, Vendor Advisory | |
| References | () https://www.drupal.org/node/2504965 - Patch | 
Information
                Published : 2015-08-18 17:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-5491
Mitre link : CVE-2015-5491
CVE.ORG link : CVE-2015-5491
JSON object : View
Products Affected
                dynamic_display_block_project
- dynamic_display_block
 
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
