VYPR

Open Atrium

by Drupal

CVEs (3)

  • CVE-2014-9502HigFeb 1, 2018
    risk 0.57cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allow remote attackers to hijack the authentication of unknown victims via vectors related to menu callbacks.

  • CVE-2014-9504HigFeb 1, 2018
    risk 0.49cvss 7.5epss 0.02

    The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance.

  • CVE-2014-9503MedFeb 1, 2018
    risk 0.42cvss 6.5epss 0.01

    The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.