First published: Tue Jul 16 2013(Updated: )
The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Acquia Commons | <=7.x-3.0 | |
Acquia Commons | =7.x-3.x-dev | |
Commons Wikis Project | <=7.x-3.0 | |
Commons Wikis Project | =7.x-3.x-dev | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1908 is considered a moderate severity vulnerability due to improper access restrictions.
To fix CVE-2013-1908, upgrade to Commons module version 7.x-3.1 or higher.
CVE-2013-1908 allows remote attackers to post arbitrary content to groups.
Versions before Commons 7.x-3.1 are affected by CVE-2013-1908.
Drupal itself is not directly affected, but the Commons module used with Drupal is vulnerable.