CVE Vulnerabilities

CVE-2014-9503

Published: Feb 01, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with access content permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.

Affected Software

Name Vendor Start Version End Version
Open_atrium Open_atrium_project 7.x-2.0 (including) 7.x-2.26 (excluding)
Open_atrium Open_atrium_project 7.x-2.0-alpha1 (including) 7.x-2.0-alpha1 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha2 (including) 7.x-2.0-alpha2 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha3 (including) 7.x-2.0-alpha3 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha4 (including) 7.x-2.0-alpha4 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha5 (including) 7.x-2.0-alpha5 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta1 (including) 7.x-2.0-beta1 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta2 (including) 7.x-2.0-beta2 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta3 (including) 7.x-2.0-beta3 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta4 (including) 7.x-2.0-beta4 (including)
Open_atrium Open_atrium_project 7.x-2.0-rc1 (including) 7.x-2.0-rc1 (including)

References