CVE-2015-4351

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
15/06/2015
Last modified:
12/04/2025

Description

The Spider Video Player module for Drupal allows remote authenticated users with the "access Spider Video Player administration" permission to delete arbitrary files via a crafted URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:web-dorado:web-dorado_spider_video_player:*:*:*:*:*:drupal:*:*