Security Advisory

CVE-2013-4498

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-05-17 20:00:00
Last updated 2024-08-06 16:45:15
Assigner redhat
State PUBLISHED

Description

The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.