CVE-2012-5539: Low severity organic groups vulnerability
The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5539?
CVE-2012-5539 has a high severity rating as it allows remote authenticated users to post to any arbitrary group.
How do I fix CVE-2012-5539?
To fix CVE-2012-5539, update the Organic Groups module to version 7.x-1.5 or later.
Which versions of the Organic Groups module are affected by CVE-2012-5539?
The affected versions of the Organic Groups module are versions 7.x-1.0 through 7.x-1.4.
What is the impact of exploiting CVE-2012-5539?
Exploiting CVE-2012-5539 allows users with pending group memberships to post content to arbitrary groups before their membership is approved.
Is there a workaround for CVE-2012-5539 if I cannot update immediately?
A potential workaround for CVE-2012-5539 is to disable the Organic Groups module until an update can be applied.