The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authenticated users to read and modify authentication tokens by leveraging the "access administration pages" Drupal permission.
References
Link Resource
https://www.drupal.org/node/2337623 Vendor Advisory
https://www.drupal.org/node/2344363 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-11-20T17:00:00

Updated: 2016-04-04T15:57:01

Reserved: 2014-11-20T00:00:00


Link: CVE-2014-9023

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-11-20T17:50:12.503

Modified: 2016-06-02T02:19:42.183


Link: CVE-2014-9023

JSON object: View

cve-icon Redhat Information

No data.

CWE