CVE-2015-5491: Dynamic Display Block Project Dynamic Display Block

Low severity, CVSS 3.5. EPSS: 1% chance of exploitation in the next 30 days.

The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.

Affected products

Published 2015-08-18. Last modified 2026-06-17.