The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2012-06-26 17:55
Updated : 2017-08-28 18:31
NVD link : CVE-2012-2721
Mitre link : CVE-2012-2721
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
moshe_weitzman
- organic_groups
drupal
- drupal