| Vulnerability Name: | CCN-94692 | ||||||
| Published: | 2014-07-16 | ||||||
| Updated: | 2014-07-16 | ||||||
| Summary: | Password Policy module for Drupal could allow a remote attacker to bypass security restrictions, caused by an error when the Password Change Tab module and the history constraint are both enabled. An attacker could exploit this vulnerability to modify the password. | ||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
| CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||
| Vulnerability Consequences: | Bypass Security | ||||||
| References: | Source: CCN Type: BID-68711 Drupal Password Policy Module 'Forced Password Change' Access Bypass Vulnerability Source: XF Type: UNKNOWN drupal-passwordpolicy-access-bypass(94692) Source: CCN Type: DRUPAL-SA-CONTRIB-2014-070 Password Policy - Access Bypass Source: CCN Type: Drupal password policy project Web site Password policy | ||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
| BACK | |||||||