MEDIUM · 4.0

CVE-2015-3404

The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certi...

Vulnerability Description

The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates."

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Certify ProjectCertify6.x-2.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3404?

CVE-2015-3404 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certi...

How severe is CVE-2015-3404?

CVE-2015-3404 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3404?

Check the references section above for vendor advisories and patch information. Affected products include: Certify Project Certify.