CVE Vulnerabilities

CVE-2015-7227

Published: Sep 17, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels.

Affected Software

NameVendorStart VersionEnd Version
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.0 (including)7.x-1.0 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.0-beta2 (including)7.x-1.0-beta2 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.1 (including)7.x-1.1 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.2 (including)7.x-1.2 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.3 (including)7.x-1.3 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.4 (including)7.x-1.4 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.5 (including)7.x-1.5 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.6 (including)7.x-1.6 (including)
Fieldable_panels_panesFieldable_panels_panes_project7.x-1.x-dev (including)7.x-1.x-dev (including)

References