Drupal Organic Groups Module Cross Site Scripting and Security Bypass Vulnerabilities
24 Jun. 2012
Summary
The Organic Groups module for Drupal is prone to a cross-site scripting vulnerability and an security-bypass vulnerability.
Credit:
The information has been provided by Ezra Barnett Gildesgame and Fox.
The original article can be found at: http://www.securityfocus.com/bid/53838
Vulnerable Systems:
* Drupal Organic Groups 6.X-2.3
* Drupal Organic Groups 6.x-2.0
Immune Systems:
* Drupal Organic Groups 6.X-2.4
An attacker can exploit the cross-site scripting issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials. Attackers can exploit the security bypass issue to bypass security restrictions and obtain sensitive information, or perform unauthorized actions; this may aid in launching further attacks.
Vendor Status:
Drupal had issued an update for this vulnerability