Unrated severityNVD Advisory· Published Dec 1, 2014· Updated Jun 17, 2026
CVE-2014-9154
CVE-2014-9154
Description
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:notify_project:notify:7.x-1.0:*:*:*:*:drupal:*:*+ 11 more
- cpe:2.3:a:notify_project:notify:7.x-1.0:*:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha1:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha2:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha3:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha4:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha5:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha6:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha7:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha8:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:alpha9:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:rc1:*:*:*:drupal:*:*
- cpe:2.3:a:notify_project:notify:7.x-1.0:rc2:*:*:*:drupal:*:*
Patches
Vulnerability mechanics
References
2- www.drupal.org/node/2320693nvdPatch
- www.drupal.org/node/2320741nvdVendor Advisory
News mentions
0No linked articles in our index yet.