CVE-2013-4498

low
Published 2014-05-17 · Modified 2026-05-06
CVSS v3
VIR risk
2.1

Description

The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
florian_weberspaces6.x-3.0
florian_weberspaces6.x-3.1
florian_weberspaces6.x-3.2
florian_weberspaces6.x-3.3
florian_weberspaces6.x-3.4
florian_weberspaces6.x-3.5
florian_weberspaces6.x-3.6
drupal drupaldrupal-

References

CWEs

CWE-264

💬 Discuss CVE-2013-4498 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.