Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Open Atrium Project Subscribe
Filtered by product Open Atrium
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9503 1 Open Atrium Project 1 Open Atrium 2018-02-27 5.5 MEDIUM 6.5 MEDIUM
The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.
CVE-2014-9502 1 Open Atrium Project 1 Open Atrium 2018-02-27 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allow remote attackers to hijack the authentication of unknown victims via vectors related to menu callbacks.
CVE-2014-9504 1 Open Atrium Project 1 Open Atrium 2018-02-27 5.0 MEDIUM 7.5 HIGH
The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance.
CVE-2014-8736 1 Open Atrium Project 1 Open Atrium 2014-11-13 5.0 MEDIUM N/A
The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node.