CVE-2015-8232
Last modified
CVE-2015-8232 is a vulnerability of currently unknown severity. The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Uc Profile Project | Uc Profile | 6.x-1.1 |
| Uc Profile Project | Uc Profile | 6.x-1.2 |
References
- https://www.drupal.org/node/2613444Patch, Vendor Advisory
- https://www.drupal.org/node/2613444Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8232?
How severe is CVE-2015-8232?
How do I fix CVE-2015-8232?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-8226The Joint Photographic Experts Group Processing Unit (JPU) d…
- CVE-2015-8227The built-in web server in Huawei VP9660 multi-point control…
- CVE-2015-8228Directory traversal vulnerability in the SFTP server in Huaw…
- CVE-2015-8229Huawei eSpace U2980 unified gateway with software before V10…
- CVE-2015-8230Memory leak in Huawei eSpace 8950 IP phones with software be…
- CVE-2015-8231Huawei eSpace 7910 and 7950 IP phones with software before V…
- CVE-2015-8233Cross-site scripting (XSS) vulnerability in the MAYO theme 7…
- CVE-2015-8234The image signature algorithm in OpenStack Glance 11.0.0 all…
- CVE-2015-8235Directory traversal vulnerability in Spiffy before 5.4.
- CVE-2015-8236Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before …
- CVE-2015-8239The SHA-2 digest support in the sudoers plugin in sudo after…
- CVE-2015-8240The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, A…
Are you affected by CVE-2015-8232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
