« Volver al listado

CVE-2013-1907

Estado: ModificadaMedia (5)—

The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1907",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-07-16T18:55:01.223",
  "references": [
    {
      "url": "http://osvdb.org/91748",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/120991/Drupal-Common-Groups-7.x-Access-Bypass-Privilege-Escalation.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/Mar/242",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/52769",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/52795",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1954762",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1954764",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1954948",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83133",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://osvdb.org/91748",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/120991/Drupal-Common-Groups-7.x-Access-Bypass-Privilege-Escalation.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2013/Mar/242",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/52769",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/52795",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1954762",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1954764",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1954948",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83133",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo Commons Group   anterior a 7.x-3.1 para Drupal utilizado en el módulo Commons anterior a 7.x-3.1, no restringe adecuadamente el acceso a los grupos, lo que permite a atacantes remotos la publicación de contenido arbitrario a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:52:22.577",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:acquia:commons:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF5614CE-043D-4579-BA4E-4729D2CD22F9",
              "versionEndIncluding": "7.x-3.0"
            },
            {
              "criteria": "cpe:2.3:a:acquia:commons:_group7.x-3.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0904FA3F-B10B-47DD-B59A-E6AE9BAF7007"
            },
            {
              "criteria": "cpe:2.3:a:acquia:commons:7.x-3.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FA305F0-248F-4A7A-9EB2-F11043BCD919"
            },
            {
              "criteria": "cpe:2.3:a:acquia:commons_group:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8479EFBB-2478-49AB-A456-06C8CF71A89B",
              "versionEndIncluding": "7.x-3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}