PT-2009-6142 · Drupal · Smartqueue Og
Publicado
2009-11-09
·
Atualizado
2009-11-10
·
CVE-2009-3921
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Smartqueue og module versions 5.x before 5.x-1.3
Smartqueue og module versions 6.x before 6.x-1.0-rc3
Description
The issue concerns the Smartqueue og module for Drupal, where it fails to verify group-node privileges in certain situations involving subqueue creation. This allows remote authenticated users to discover arbitrary organic group names by reading confirmation messages.
Recommendations
For Smartqueue og module versions 5.x before 5.x-1.3, update to version 5.x-1.3 or later.
For Smartqueue og module versions 6.x before 6.x-1.0-rc3, update to version 6.x-1.0-rc3 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Smartqueue Og