CVE-2015-7229
Last modified
CVE-2015-7229 is a vulnerability of currently unknown severity. The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission.. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Twitter Project | 6.x-5.0 | — | |
| Twitter Project | 6.x-5.1 | — | |
| Twitter Project | 6.x-5.x | Dev | |
| Twitter Project | 7.x-5.0 | — | |
| Twitter Project | 7.x-5.1 | — | |
| Twitter Project | 7.x-5.2 | — | |
| Twitter Project | 7.x-5.3 | — | |
| Twitter Project | 7.x-5.4 | — | |
| Twitter Project | 7.x-5.5 | — | |
| Twitter Project | 7.x-5.6 | — | |
| Twitter Project | 7.x-5.7 | — | |
| Twitter Project | 7.x-5.8 | — | |
| Twitter Project | 7.x-6.0 | Alpha1 |
References
- https://www.drupal.org/node/2565827Patch, Vendor Advisory
- https://www.drupal.org/node/2565827Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7229?
How severe is CVE-2015-7229?
How do I fix CVE-2015-7229?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-7223The WebExtension APIs in Mozilla Firefox before 43.0 allow r…
- CVE-2015-7224puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers …
- CVE-2015-7225Tinfoil Devise-two-factor before 2.0.0 does not strictly fol…
- CVE-2015-7226The Administration Views module 7.x-1.x before 7.x-1.5 for D…
- CVE-2015-7227The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for…
- CVE-2015-7228The RESTful module 7.x-1.x before 7.x-1.3 for Drupal does no…
- CVE-2015-7230The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal…
- CVE-2015-7231The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.…
- CVE-2015-7232Cross-site scripting (XSS) vulnerability in unspecified admi…
- CVE-2015-7233Cross-site request forgery (CSRF) vulnerability in the OSF m…
- CVE-2015-7234The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the O…
- CVE-2015-7235Multiple SQL injection vulnerabilities in dex_reservations.p…
Are you affected by CVE-2015-7229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
