cbcvebase.
CVE-2015-2559
published 2015-03-25

CVE-2015-2559: Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same…

PriorityP422low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.64%
74.0th percentile
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

Affected

3 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
drupaldrupal>= 6.0 < 6.356.35
drupaldrupal>= 7.0 < 7.357.35

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.