CVE-2013-4228: Medium severity organic groups vulnerability
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4228?
CVE-2013-4228 has a moderate severity rating due to its potential to allow unauthorized access to private group content.
How do I fix CVE-2013-4228?
To fix CVE-2013-4228, upgrade the Organic Groups module to version 7.x-2.3 or later.
What versions are affected by CVE-2013-4228?
CVE-2013-4228 affects all versions of the Organic Groups module from 7.x-2.0 to 7.x-2.2.
Can CVE-2013-4228 be exploited remotely?
Yes, CVE-2013-4228 can be exploited remotely by authenticated users.
What implications does CVE-2013-4228 have for users?
CVE-2013-4228 allows users to guess node IDs and gain access to content in arbitrary private groups.