CVE-2013-7065: Medium severity Organic Groups Project Organic Groups Drupal vulnerability
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups via a group audience field, as demonstrated by the oggroupref field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/og_group_ref (Organic Groups OG module 7.x-2.x)to a version that resolves this vulnerability.Fixed in 7.x-2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7065?
CVE-2013-7065 is rated as a moderate severity vulnerability that allows remote attackers to bypass access restrictions.
How do I fix CVE-2013-7065?
To fix CVE-2013-7065, update the Organic Groups module to version 7.x-2.3 or later.
What types of access are affected by CVE-2013-7065?
CVE-2013-7065 allows unauthorized posting to arbitrary groups via the group audience field.
Which Drupal versions are vulnerable to CVE-2013-7065?
Versions of the Organic Groups module prior to 7.x-2.3, including 7.x-2.0 and its alpha, beta, and release candidate versions, are vulnerable.
Who is impacted by CVE-2013-7065?
Organizations using affected versions of the Organic Groups module on their Drupal sites are at risk of exploitation due to this vulnerability.