CVE-2014-8734: Low severity organic groups vulnerability
Published Nov 12, 2014
·Updated
The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified vectors.
Affected Software
3 affected components
Drupal Organic Groups Menu<=7.x-2.1
Drupal Organic Groups Menu=7.x-2.0
Drupal Organic Groups Menu=7.x-2.x-dev
Remediation
Patch Available
Patch Available
Event History
Nov 12, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8734?
CVE-2014-8734 is classified as a moderate level vulnerability.
2
How do I fix CVE-2014-8734?
To fix CVE-2014-8734, upgrade the Organic Groups Menu module to version 7.x-2.2 or later.
3
Who is affected by CVE-2014-8734?
CVE-2014-8734 affects remote authenticated users who have the 'access administration pages' permission in Drupal.
4
What can attackers do in CVE-2014-8734?
Attackers exploiting CVE-2014-8734 can change module settings, potentially compromising site configuration.
5
Is CVE-2014-8734 a widespread issue?
CVE-2014-8734 affects all versions of the Organic Groups Menu module prior to 7.x-2.2, making it a concern for Drupal sites using this module.