VWE-2015-0908 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2015-0908
This page is a chapter in Info Known Vulnerabilities

This page has been seen 360,231 times.

    • Created by on
      Last updated by on
Common NameRunaway Graffiti Vulnerability
VWE-IDVWE-2015-0908
Related ReportNone
SeverityMEDIUM
Exploit DifficultyNORMAL
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation.
DiscoveredMarch 12, 2015
ResolvedMarch 13, 2015
Patches Available4.0.1 Patch Level 2
4.0.0 Patch Level 2
WorkaroundIn the Admin Panel, disable "Feed" under Structures > Content Types.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.