First published: Tue Jul 16 2013(Updated: )
The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Acquia Commons | <=7.x-3.0 | |
Acquia Commons | =_group7.x-3.x-dev | |
Acquia Commons | =7.x-3.x-dev | |
Acquia Commons | <=7.x-3.0 | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1907 has been classified as a moderate severity vulnerability.
To fix CVE-2013-1907, upgrade the Commons Group module to version 7.x-3.1 or newer.
CVE-2013-1907 may allow remote attackers to post arbitrary content to groups, leading to potential misuse of group resources.
CVE-2013-1907 affects Commons Group module versions prior to 7.x-3.1.
No, CVE-2013-1907 specifically impacts those using the Commons Group module prior to version 7.x-3.1.