Drupal Organic Groups Vocabulary Module Security Bypass Vulnerability
SECUNIA ADVISORY ID: SA37060
VERIFY ADVISORY: http://secunia.com/advisories/37060/
DESCRIPTION: A vulnerability has been reported in the Organic Groups Vocabulary module for Drupal, which can be exploited by malicious users to bypass certain security restrictions.
An error in handling of access permissions can be exploited by a group member to view, edit, and create vocabularies of other groups.
The vulnerability is reported in versions prior to 6.x-1.0.
SOLUTION: Update to version 6.x-1.0. http://drupal.org/node/604354
PROVIDED AND/OR DISCOVERED BY: The vendor credits FGM and Ki.
ORIGINAL ADVISORY: SA-CONTRIB-2009-071: http://drupal.org/node/604514
———————————————————————-
