CVE-2015-5515: Views Bulk Operations Project Views Bulk Operations

Medium severity, CVSS 4.9. EPSS: 1.6% chance of exploitation in the next 30 days.

The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.

Affected products

  • Views Bulk Operations Project Views Bulk Operations: version 6.x-1.17 only; version 6.x-1.x only; version 7.x-3.0 only; version 7.x-3.1 only; version 7.x-3.2 only; version 7.x-3.x only

Published 2015-08-18. Last modified 2026-06-17.