CVE Vulnerabilities

CVE-2014-9503

Published: Feb 01, 2018 | Modified: Feb 27, 2018
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with access content permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.

Affected Software

Name Vendor Start Version End Version
Open_atrium Open_atrium_project 7.x-2.0 (including) 7.x-2.26 (excluding)
Open_atrium Open_atrium_project 7.x-2.0-alpha1 (including) 7.x-2.0-alpha1 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha2 (including) 7.x-2.0-alpha2 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha3 (including) 7.x-2.0-alpha3 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha4 (including) 7.x-2.0-alpha4 (including)
Open_atrium Open_atrium_project 7.x-2.0-alpha5 (including) 7.x-2.0-alpha5 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta1 (including) 7.x-2.0-beta1 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta2 (including) 7.x-2.0-beta2 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta3 (including) 7.x-2.0-beta3 (including)
Open_atrium Open_atrium_project 7.x-2.0-beta4 (including) 7.x-2.0-beta4 (including)
Open_atrium Open_atrium_project 7.x-2.0-rc1 (including) 7.x-2.0-rc1 (including)

References