MEDIUM · 4.9

CVE-2013-7068

The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.

Vulnerability Description

The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.

CVSS Score

4.9

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Organic Groups ProjectOrganic Groups7.x-2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-7068?

CVE-2013-7068 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.

How severe is CVE-2013-7068?

CVE-2013-7068 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-7068?

Check the references section above for vendor advisories and patch information. Affected products include: Organic Groups Project Organic Groups.