Vulnerabilities > Florian Weber

DATE CVE VULNERABILITY TITLE RISK
2014-05-17 CVE-2013-4498 Permissions, Privileges, and Access Controls vulnerability in Florian Weber Spaces
The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.
network
high complexity
florian-weber drupal CWE-264
2.1
2012-07-18 CVE-2012-2303 Permissions, Privileges, and Access Controls vulnerability in Florian Weber Spaces
The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.
network
low complexity
florian-weber drupal CWE-264
7.5