CVE-2015-7230

low
Published 2015-09-17 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows remote authenticated users with certain permissions to bypass node and field validation by saving a node.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/node/2553971

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/node/2484229

Application impact

VendorProductVersionsFixed
workbench_email_projectworkbench_email7.x-3.0
workbench_email_projectworkbench_email7.x-3.1
workbench_email_projectworkbench_email7.x-3.2
workbench_email_projectworkbench_email7.x-3.3

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.