CVE-2013-4228 Information
Feb 14, 2021
cve
Description
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups which allows remote authenticated users to guess node IDs subscribe to and read the content of arbitrary private groups via unspecified vectors.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
http://www.openwall.com/lists/oss-security/2013/08/10/1 http://www.securityfocus.com/bid/61708 https://drupal.org/node/2059755 https://drupal.org/node/2059765 https://exchange.xforce.ibmcloud.com/vulnerabilities/86328
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: