Security Advisory

CVE-2015-2559

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2015-03-25 14:00:00
Last updated 2024-08-06 05:17:27
Assigner mitre
State PUBLISHED

Description

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.