CVE-2015-5496: PASS2PDF Project PASS2PDF

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain user passwords via unspecified vectors.

Affected products

Published 2015-08-18. Last modified 2026-06-17.