The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.drupal.org/node/2365259 | patch |
https://www.drupal.org/node/2365685 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98445 | vdb entry |