CVE-2015-4351: Web-Dorado Spider Video Player

Medium severity, CVSS 4.9. EPSS: 1.1% chance of exploitation in the next 30 days.

The Spider Video Player module for Drupal allows remote authenticated users with the "access Spider Video Player administration" permission to delete arbitrary files via a crafted URL.

Affected products

  • Web-Dorado Web-Dorado Spider Video Player: any version

Published 2015-06-15. Last modified 2026-06-17.