PT-2014-8793 · Twilio · Twilio
Karolrybak
·
Published
2014-11-20
·
Updated
2016-06-02
·
CVE-2014-9023
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Twilio module versions 7.x-1.x through 7.x-1.8
Description
The issue allows remote authenticated users to read and modify authentication tokens by leveraging the "access administration pages" Drupal permission, due to improper access restriction to the Twilio administration pages.
Recommendations
For Twilio module versions 7.x-1.x through 7.x-1.8, update to version 7.x-1.9 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Twilio