Chaos Tool Suite Project ctools for Drupal 7.x-1.x dev

CPE Details

Chaos Tool Suite Project ctools for Drupal 7.x-1.x dev
7.x-1.x
2015-06-18
14h46 +00:00
2015-06-18
15h16 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.x:dev:*:*:*:drupal:*:*

Informations

Vendor

chaos_tool_suite_project

Product

ctools

Version

7.x-1.x

Update

dev

Target Software

drupal

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2015-7875 2017-08-07 15h00 +00:00 ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.
7.5
High
CVE-2013-1925 2013-07-16 16h00 +00:00 The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
3.5
CVE-2012-2082 2012-08-14 21h00 +00:00 Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.
2.1