The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.drupal.org/node/2430043 | patch |
http://www.securityfocus.com/bid/75278 | vdb entry |
https://www.drupal.org/node/2507645 | patch vendor advisory |
http://www.openwall.com/lists/oss-security/2015/07/04/4 | mailing list |