VYPR
Unrated severityNVD Advisory· Published Jul 9, 2008· Updated Apr 23, 2026

CVE-2008-3095

CVE-2008-3095

Description

Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting in Drupal Organic Groups module allows group owners to inject arbitrary script, potentially leading to admin access.

Vulnerability

The Organic Groups module for Drupal versions 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1 contains a cross-site scripting (XSS) vulnerability. The module displays certain user-supplied values without proper filtering, allowing malicious group owners to inject arbitrary HTML and script code. The attack requires that audience checkboxes are disabled (enabled by default) and the site allows untrusted users to create groups [1].

Exploitation

An attacker must be an authenticated user with group owner permissions. They create a group and convince other users to join. When a victim attempts to start a new discussion in the group, the injected script executes. The attack does not require user interaction beyond joining the group and initiating a discussion [1].

Impact

Successful exploitation allows the attacker to inject arbitrary web script or HTML, which can lead to administrator access for the malicious user. The XSS can be used to steal session cookies, perform actions on behalf of the victim, or escalate privileges within the Drupal site [1].

Mitigation

The vulnerability is fixed in Organic Groups 5.x-7.3 for Drupal 5.x and 6.x-1.0-RC1 for Drupal 6.x. Users should upgrade to these versions and run update.php. No workarounds are provided in the advisory [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.