The Organic Groups (OG) Vocabulary module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with certain administrator permissions to modify the vocabularies of other groups via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://drupal.org/node/1441086 | |
http://www.openwall.com/lists/oss-security/2012/04/07/1 | mailing list |
http://drupalcode.org/project/og_vocab.git/commitdiff/cd8de08 | patch exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53902 | vdb entry |
http://www.osvdb.org/79336 | vdb entry |
https://drupal.org/node/1441450 | patch vendor advisory |
http://secunia.com/advisories/48020 | third party advisory vendor advisory |