CVE Database
/

CVE-2013-4228

Back to search

CVE-2013-4228

Published: Feb 18, 2020

Modified: Aug 6, 2024

PUBLISHED

Description

The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors.

VendorProductVersions

n/a

Organic Groups (OG) module

affected
7.x-2.x before 7.x-2.3

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now