The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/01/04/6 | issue tracking mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/99657 | vdb entry third party advisory |
https://www.drupal.org/node/2394979 | mitigation vendor advisory |
https://www.drupal.org/node/2395045 | patch vendor advisory |