Vulnerabilities
Vulnerable Software
Florian Weber:  >> Spaces  Security Vulnerabilities
The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.
CVSS Score
2.1
EPSS Score
0.002
Published
2014-05-17
The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.
CVSS Score
7.5
EPSS Score
0.008
Published
2012-07-18


Contact Us

Shodan ® - All rights reserved