Drupal Organic Groups Menu Module Access Bypass Vulnerability
BID:71067
Info
Drupal Organic Groups Menu Module Access Bypass Vulnerability
| Bugtraq ID: | 71067 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-8734 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2014 12:00AM |
| Updated: | Nov 12 2014 12:00AM |
| Credit: | Lucas D Hedding |
| Vulnerable: |
Drupal Organic Groups Menu 7.x-2.1 |
| Not Vulnerable: |
Drupal Organic Groups Menu 7.x-2.2 |
Discussion
Drupal Organic Groups Menu Module Access Bypass Vulnerability
The Organic Groups Menu module for Drupal is prone to an access-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Organic Groups Menu 7.x-2.x versions prior to 7.x-2.2 are vulnerable.
The Organic Groups Menu module for Drupal is prone to an access-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Organic Groups Menu 7.x-2.x versions prior to 7.x-2.2 are vulnerable.
Exploit / POC
Drupal Organic Groups Menu Module Access Bypass Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
References
Drupal Organic Groups Menu Module Access Bypass Vulnerability
References:
References:
- Drupal Organic Groups HomePage (Drupal)
- Organic Groups Menu Download Page (Drupal)
- SA-CONTRIB-2014-105 - OG Menu - Access Bypass (Drupal)