Chaos Tool Suite Project ctools for Drupal 7.x-1.0 release candidate 2

CPE Details

Chaos Tool Suite Project ctools for Drupal 7.x-1.0 release candidate 2
7.x-1.0
2015-06-18
14h49 +00:00
2015-06-18
15h15 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:rc2:*:*:*:drupal:*:*

Informations

Vendor

chaos_tool_suite_project

Product

ctools

Version

7.x-1.0

Update

rc2

Target Software

drupal

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2015-7875 2017-08-07 15h00 +00:00 ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.
7.5
High
CVE-2015-4398 2015-06-16 15h00 +00:00 Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.
5.8
CVE-2015-4375 2015-06-15 12h00 +00:00 The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity.
4.3
CVE-2013-1925 2013-07-16 16h00 +00:00 The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
3.5
CVE-2012-2082 2012-08-14 21h00 +00:00 Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.
2.1