The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates."
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2015-04-22T22:00:00

Updated: 2016-12-02T20:57:01

Reserved: 2015-04-22T00:00:00


Link: CVE-2015-3404

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-04-22T22:59:00.063

Modified: 2016-12-06T03:00:52.457


Link: CVE-2015-3404

JSON object: View

cve-icon Redhat Information

No data.

CWE