Chaos Tool Suite Project Ctools vulnerabilities
11 known vulnerabilities affecting chaos_tool_suite_project/ctools.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM6LOW4
Vulnerabilities
Page 1 of 1
CVE-2015-7875P4HIGHCVSS 7.5v6.x-1.0v6.x-1.1+21 more2017-08-07
CVE-2015-7875 [HIGH] CWE-264 CVE-2015-7875: ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permi
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.
nvd
CVE-2010-1546P4MEDIUMCVSS 6.0v6.x-1.0v6.x-1.1+3 more2010-05-21
CVE-2010-1546 [MEDIUM] CWE-94 CVE-2010-1546: Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTo
Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with "administer page manager" privileges, to execute arbitrary PHP code via input to a text area, related to (1) the page_manager_page_import_subtask_validate function in page_m
nvd
CVE-2010-1547P4MEDIUMCVSS 6.8v6.x-1.0v6.x-1.1+3 more2010-05-21
CVE-2010-1547 [MEDIUM] CWE-352 CVE-2010-1547: Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) modu
Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable a page via a q=admin/build/pages/nojs/enable/ value or (2) disable a page via a q=admin/build/pages/nojs/disable/ value.
nvd
CVE-2015-4398P4MEDIUMCVSS 5.8≤ 6.x-1.11v7.x-1.0+6 more2015-06-16
CVE-2015-4398 [MEDIUM] CVE-2015-4398: Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x befo
Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.
nvd
CVE-2015-4375P4MEDIUMCVSS 4.3v7.x-1.0v7.x-1.1+5 more2015-06-15
CVE-2015-4375 [MEDIUM] CWE-200 CVE-2015-4375: The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to ob
The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity.
nvd
CVE-2015-6665P4MEDIUMCVSS 4.3v6.x-1.0v6.x-1.1+12 more2015-08-24
CVE-2015-6665 [MEDIUM] CWE-79 CVE-2015-6665: Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctool
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
nvd
CVE-2013-1925P4LOWCVSS 3.5v7.x-1.0v7.x-1.1+2 more2013-07-16
CVE-2013-1925 [LOW] CWE-264 CVE-2013-1925: The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict no
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
nvd
CVE-2010-2010P4MEDIUMCVSS 4.3v6.x-1.0v6.x-1.1+3 more2010-05-21
CVE-2010-2010 [MEDIUM] CWE-79 CVE-2010-2010: Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.
nvd
CVE-2010-1548P4LOWCVSS 3.5v6.x-1.0v6.x-1.1+3 more2010-05-21
CVE-2010-1548 [LOW] CWE-264 CVE-2010-1548: The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for D
The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.
nvd
CVE-2012-2082P4LOWCVSS 2.1v7.x-1.0v7.x-1.x2012-08-14
CVE-2012-2082 [LOW] CWE-79 CVE-2012-2082: Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before
Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.
nvd
CVE-2012-5559P4LOWCVSS 2.6v6.x-1.0v6.x-1.1+9 more2012-12-03
CVE-2012-5559 [LOW] CWE-79 CVE-2012-5559: Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite
Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web script or HTML via the page title.
nvd