Security Advisory

CVE-2013-7065

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-04-29 14:00:00
Last updated 2024-08-06 17:53:46
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups via a group audience field, as demonstrated by the og_group_ref field.