Total vulnerabilities in the database
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.
Software | From | Fixed in |
---|---|---|
ubercart / ubercart | 7.x-3.0 | 7.x-3.0.x |
ubercart / ubercart | 7.x-3.0-alpha1 | 7.x-3.0-alpha1.x |
ubercart / ubercart | 7.x-3.0-rc4 | 7.x-3.0-rc4.x |
ubercart / ubercart | 7.x-3.0-alpha2 | 7.x-3.0-alpha2.x |
ubercart / ubercart | 7.x-3.0-beta1 | 7.x-3.0-beta1.x |
ubercart / ubercart | 7.x-3.5 | 7.x-3.5.x |
ubercart / ubercart | 7.x-3.0-rc2 | 7.x-3.0-rc2.x |
ubercart / ubercart | 7.x-3.3 | 7.x-3.3.x |
ubercart / ubercart | 7.x-3.2 | 7.x-3.2.x |
ubercart / ubercart | 7.x-3.0-beta3 | 7.x-3.0-beta3.x |
ubercart / ubercart | 7.x-3.7 | 7.x-3.7.x |
ubercart / ubercart | 7.x-3.4 | 7.x-3.4.x |
ubercart / ubercart | 7.x-3.0-rc3 | 7.x-3.0-rc3.x |
ubercart / ubercart | 7.x-3.1 | 7.x-3.1.x |
ubercart / ubercart | 7.x-3.0-beta4 | 7.x-3.0-beta4.x |
ubercart / ubercart | 7.x-3.x-dev | 7.x-3.x-dev.x |
ubercart / ubercart | 7.x-3.6 | 7.x-3.6.x |
ubercart / ubercart | 7.x-3.0-rc1 | 7.x-3.0-rc1.x |
ubercart / ubercart | 7.x-3.0-beta2 | 7.x-3.0-beta2.x |
ubercart / ubercart | 7.x-3.0-alpha3 | 7.x-3.0-alpha3.x |