CVE-2015-4375
Summary
| CVE | CVE-2015-4375 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-15 14:59:32 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.0 | All | All | All |
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.1 | All | All | All |
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.2 | All | All | All |
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.3 | All | All | All |
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.4 | All | All | All |
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.5 | All | All | All |
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.6 | All | All | All |
| Application | Chaos Tool Suite Project | Ctools | 7.x-1.6 | rc1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE requests for Drupal contributed modules | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - CVE requests for Drupal contributed modules (from SA-CONTRIB-2015-034 to SA-CONTRIB-2015-099) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| SA-CONTRIB-2015-079 - Chaos tool suite (ctools) - Multiple vulnerabilities | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch, Vendor Advisory |
| ctools 7.x-1.7 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.