CVE-2007-3690
Status: ModifiedHigh (7.8)—
The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.78%
- Percentile among all scored CVEs: 78
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://drupal.org/node/152806
- http://drupal.org/node/158022
- http://drupal.org/node/158025
- http://osvdb.org/37896
- http://secunia.com/advisories/25999
- http://www.securityfocus.com/bid/24862
- http://www.vupen.com/english/advisories/2007/2469
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35318
- http://drupal.org/node/152806
- http://drupal.org/node/158022
- http://drupal.org/node/158025
- http://osvdb.org/37896
- http://secunia.com/advisories/25999
- http://www.securityfocus.com/bid/24862
- http://www.vupen.com/english/advisories/2007/2469
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35318
Raw JSON (NVD)
Show
{
"id": "CVE-2007-3690",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-07-11T17:30:00.000",
"references": [
{
"url": "http://drupal.org/node/152806",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://drupal.org/node/158022",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://drupal.org/node/158025",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37896",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25999",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24862",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2469",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35318",
"source": "cve@mitre.org"
},
{
"url": "http://drupal.org/node/152806",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupal.org/node/158022",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupal.org/node/158025",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37896",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25999",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/24862",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2469",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35318",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments."
},
{
"lang": "es",
"value": "El módulo Forward anterior a 4.7-1.1 y 5.x anterior a 5.x-1.0 para Drupal permite a atacantes remotos leer anotaciones restringidas en (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, y otros módulos de acceso a nodos no especificados, mediante argumentos URL modificados."
}
],
"lastModified": "2026-06-16T22:42:32.063",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:forward_module:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53DD8ACA-D5BC-4884-9381-60C651B540AB",
"versionEndIncluding": "4.7"
},
{
"criteria": "cpe:2.3:a:drupal:forward_module:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE2FCC53-05F2-4953-9F93-8C3B6FFC900F",
"versionEndIncluding": "5.x-1.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}