4
CVSSv2

CVE-2013-4228

Published: 18/02/2020 Updated: 26/02/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x prior to 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

organic groups project organic groups 7.x-2.0

organic groups project organic groups 7.x-2.1

organic groups project organic groups 7.x-2.2