Vulnerabilities > Entityform Block Project

DATE CVE VULNERABILITY TITLE RISK
2015-08-18 CVE-2015-5493 Permissions, Privileges, and Access Controls vulnerability in Entityform Block Project Entityform Block
The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not properly check permissions when a form is locked to a role, which allows remote attackers to obtain access to certain entityforms via unspecified vectors.
network
low complexity
entityform-block-project CWE-264
5.0