PT-2009-6142 · Drupal · Smartqueue Og

Publicado

2009-11-09

·

Atualizado

2009-11-10

·

CVE-2009-3921

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Smartqueue og module versions 5.x before 5.x-1.3 Smartqueue og module versions 6.x before 6.x-1.0-rc3
Description The issue concerns the Smartqueue og module for Drupal, where it fails to verify group-node privileges in certain situations involving subqueue creation. This allows remote authenticated users to discover arbitrary organic group names by reading confirmation messages.
Recommendations For Smartqueue og module versions 5.x before 5.x-1.3, update to version 5.x-1.3 or later. For Smartqueue og module versions 6.x before 6.x-1.0-rc3, update to version 6.x-1.0-rc3 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3921

Produtos afetados

Smartqueue Og