The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain sensitive information (private group names) via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/30070 | vdb entry third party advisory |
http://drupal.org/node/277873 | patch vendor advisory |
http://secunia.com/advisories/30928 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43578 | vdb entry third party advisory |