Security Advisory
CVE-2015-7306
4.9
Vulnerability Description
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.
Published Date
September 21, 2015
Official Source
NIST NVD Advisory