Show plain JSON{"id": "CVE-2014-9023", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2014-11-20T17:50:12.503", "references": [{"url": "https://www.drupal.org/node/2337623", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.drupal.org/node/2344363", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.drupal.org/node/2337623", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.drupal.org/node/2344363", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-264"}]}], "descriptions": [{"lang": "en", "value": "The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authenticated users to read and modify authentication tokens by leveraging the \"access administration pages\" Drupal permission."}, {"lang": "es", "value": "El m\u00f3dulo Twilio 7.x-1.x en versiones anteriores a 7.x-1.9 para Drupal no restringe adecuadamente el acceso a las p\u00e1ginas de administraci\u00f3n de Twilio, lo que permite a usuarios remotos autenticados leer y modificar tokens de autenticaci\u00f3n mediante el aprovechamiento del permiso de \"acceso a p\u00e1ginas de administraci\u00f3n\" de Drupal."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:twilio_project:twilio:7.x-1.1:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "B4E8FE05-741E-4DC6-A2A0-8E8FAECBE2BA"}, {"criteria": "cpe:2.3:a:twilio_project:twilio:7.x-1.2:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "90BAD051-595D-4E2E-97CB-6934BE3D893B"}, {"criteria": "cpe:2.3:a:twilio_project:twilio:7.x-1.4:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "F41C2559-AD87-4316-AD9E-535F30980809"}, {"criteria": "cpe:2.3:a:twilio_project:twilio:7.x-1.5:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "7AEFC2B5-87FE-4598-9B38-BAC82F9830D2"}, {"criteria": "cpe:2.3:a:twilio_project:twilio:7.x-1.6:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "5C5DA7F5-FD11-404F-AD5A-735A8D68EF56"}, {"criteria": "cpe:2.3:a:twilio_project:twilio:7.x-1.8:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "B97FFE10-93CE-4C07-8124-7805DDB13176"}, {"criteria": "cpe:2.3:a:twilio_project:twilio:7.x-1.9:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "7F3B9B6B-8098-4E16-BC80-36EC596221D6"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}