{"api_version":"1","generated_at":"2026-07-23T08:06:59+00:00","cve":"CVE-2015-7226","urls":{"html":"https://cve.report/CVE-2015-7226","api":"https://cve.report/api/cve/CVE-2015-7226.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-7226","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-7226"},"summary":{"title":"CVE-2015-7226","description":"The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-09-17 16:59:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.drupal.org/node/2529378","name":"https://www.drupal.org/node/2529378","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Administration Views - Critical - Information Disclosure - SA-CONTRIB-2015-132 | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.drupal.org/node/2529366","name":"https://www.drupal.org/node/2529366","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"admin_views 7.x-1.5 | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/75697","name":"http://www.securityfocus.com/bid/75697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Administration Views Module Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://cgit.drupalcode.org/admin_views/commit/?id=44098bb","name":"http://cgit.drupalcode.org/admin_views/commit/?id=44098bb","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"admin_views - For more information about this repository, visit the project page at http://drupal.org/project/admin_views","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-7226","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7226","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"7226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"administration_views_project","cpe5":"administration_views","cpe6":"7.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"administration_views_project","cpe5":"administration_views","cpe6":"7.x-1.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"administration_views_project","cpe5":"administration_views","cpe6":"7.x-1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"administration_views_project","cpe5":"administration_views","cpe6":"7.x-1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"administration_views_project","cpe5":"administration_views","cpe6":"7.x-1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"administration_views_project","cpe5":"administration_views","cpe6":"7.x-1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7226","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"administration_views_project","cpe5":"administration_views","cpe6":"7.x-1.x","cpe7":"dev","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:43:45.815Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.drupal.org/node/2529366"},{"name":"75697","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/75697"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.drupal.org/node/2529378"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://cgit.drupalcode.org/admin_views/commit/?id=44098bb"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-07-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-25T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.drupal.org/node/2529366"},{"name":"75697","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/75697"},{"tags":["x_refsource_MISC"],"url":"https://www.drupal.org/node/2529378"},{"tags":["x_refsource_CONFIRM"],"url":"http://cgit.drupalcode.org/admin_views/commit/?id=44098bb"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-7226","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.drupal.org/node/2529366","refsource":"CONFIRM","url":"https://www.drupal.org/node/2529366"},{"name":"75697","refsource":"BID","url":"http://www.securityfocus.com/bid/75697"},{"name":"https://www.drupal.org/node/2529378","refsource":"MISC","url":"https://www.drupal.org/node/2529378"},{"name":"http://cgit.drupalcode.org/admin_views/commit/?id=44098bb","refsource":"CONFIRM","url":"http://cgit.drupalcode.org/admin_views/commit/?id=44098bb"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-7226","datePublished":"2015-09-17T16:00:00.000Z","dateReserved":"2015-09-17T00:00:00.000Z","dateUpdated":"2024-08-06T07:43:45.815Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-09-17 16:59:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:administration_views_project:administration_views:7.x-1.0:*:*:*:*:drupal:*:*","matchCriteriaId":"12E31109-601D-4962-998C-0AE06A4A2587"},{"vulnerable":true,"criteria":"cpe:2.3:a:administration_views_project:administration_views:7.x-1.0:rc1:*:*:*:drupal:*:*","matchCriteriaId":"D2375B7C-3AEE-44D5-B851-337259C60862"},{"vulnerable":true,"criteria":"cpe:2.3:a:administration_views_project:administration_views:7.x-1.1:*:*:*:*:drupal:*:*","matchCriteriaId":"0BB101A0-9F5E-4ACF-85F4-2FB747811469"},{"vulnerable":true,"criteria":"cpe:2.3:a:administration_views_project:administration_views:7.x-1.2:*:*:*:*:drupal:*:*","matchCriteriaId":"BE803C20-D397-445C-8932-E659ABAA1F8D"},{"vulnerable":true,"criteria":"cpe:2.3:a:administration_views_project:administration_views:7.x-1.3:*:*:*:*:drupal:*:*","matchCriteriaId":"4CD5FEA7-7DF5-490B-8BD4-66AE53D6C22E"},{"vulnerable":true,"criteria":"cpe:2.3:a:administration_views_project:administration_views:7.x-1.4:*:*:*:*:drupal:*:*","matchCriteriaId":"2842E1D2-DC11-4D59-85AA-BE0A7B631B00"},{"vulnerable":true,"criteria":"cpe:2.3:a:administration_views_project:administration_views:7.x-1.x:dev:*:*:*:drupal:*:*","matchCriteriaId":"C9613673-C043-46CA-BF5E-B37533834693"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"7226","Ordinal":"1","Title":"CVE-2015-7226","CVE":"CVE-2015-7226","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"7226","Ordinal":"1","NoteData":"The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.","Type":"Description","Title":"CVE-2015-7226"},{"CveYear":"2015","CveId":"7226","Ordinal":"2","NoteData":"2015-09-17","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"7226","Ordinal":"3","NoteData":"2016-11-25","Type":"Other","Title":"Modified"}]}}}