CVE-2015-7229
Summary
| CVE | CVE-2015-7229 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-09-17 16:59:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Twitter Project | 6.x-5.0 | All | All | All | |
| Application | Twitter Project | 6.x-5.1 | All | All | All | |
| Application | Twitter Project | 6.x-5.x | dev | All | All | |
| Application | Twitter Project | 7.x-5.0 | All | All | All | |
| Application | Twitter Project | 7.x-5.1 | All | All | All | |
| Application | Twitter Project | 7.x-5.2 | All | All | All | |
| Application | Twitter Project | 7.x-5.3 | All | All | All | |
| Application | Twitter Project | 7.x-5.4 | All | All | All | |
| Application | Twitter Project | 7.x-5.5 | All | All | All | |
| Application | Twitter Project | 7.x-5.6 | All | All | All | |
| Application | Twitter Project | 7.x-5.7 | All | All | All | |
| Application | Twitter Project | 7.x-5.8 | All | All | All | |
| Application | Twitter Project | 7.x-6.0 | alpha1 | All | All | |
| Application | Twitter Project | 7.x-6.0 | alpha2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| twitter 7.x-6.0 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch |
| twitter 7.x-5.9 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch |
| twitter 6.x-5.2 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch |
| Twitter - Moderately Critical - Access bypass - SA-CONTRIB-2015-146 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.