VYPR

Organic Groups module

by Drupal

CVEs (1)

  • CVE-2013-4228MedFeb 18, 2020
    risk 0.28cvss 4.3epss 0.01

    The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary…