LOW · 3.5

CVE-2015-2559

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a craft...

Vulnerability Description

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
DebianDebian Linux7.0
DrupalDrupal>= 6.0, < 6.35

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2559?

CVE-2015-2559 is a vulnerability with a CVSS score of 3.5 (LOW). Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a craft...

How severe is CVE-2015-2559?

CVE-2015-2559 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2559?

Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Drupal Drupal.