CVE-2014-9503
01.02.2018, 17:29
The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.Enginsight
Vendor | Product | Version |
---|---|---|
open_atrium_project | open_atrium | 7.x-2.0 ≤ 𝑥 < 7.x-2.26 |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
open_atrium_project | open_atrium | 7.x-2.0:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References