CVE-2015-5491: Dynamic Display Block Project Dynamic Display Block
Low severity, CVSS 3.5. EPSS: 1% chance of exploitation in the next 30 days.
The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.
Affected products
- Dynamic Display Block Project Dynamic Display Block: version 7.x-1.0 only; version 7.x-1.x only
Published 2015-08-18. Last modified 2026-06-17.