← Back

CVE-2015-2559

nvd nist
Published: Mar 25, 2015Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

Affected (3)

1 product
Debian Linux
1 product
Drupal
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
From 6.0 to 6.35
From 7.0 to 7.35

References (6)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.