Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Commons Group模块权限许可和访问控制漏洞
Vulnerability Description
Commons是一套用于创建内部或外部社区的解决方案。Commons Group是用于Drupal中的一个扩展模块,该模块为Commons分布提供了一个Organic Groups功能。Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Commons模块7.x-3.1之前的版本中使用的Drupal的Commons Group模块7.x-3.1之前的版本中存在访问绕过和提权漏洞,该漏洞源于程序没有正确限制对组的访问权限。远程攻击者可利用该漏洞向组提交任意内容。
CVSS Information
N/A
Vulnerability Type
N/A