Open Atrium
Vendor:
First CVE: Nov 12, 2014 · Active for 11 years
4
Total CVEs
More Total CVEs than 75% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Open Atrium over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2014
11 years ago
Most Recent CVE
Feb 1, 2018
3,099 days ago
CVE Severity & Scoring
Open Atrium4 CVEs
50%
50%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (75.0%)
Unknown1 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High0 (0.0%)
Unknown1 (25.0%)
User Interaction
None2 (50.0%)
Unknown1 (25.0%)
Required1 (25.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None2 (50.0%)
Unknown1 (25.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9503MEDIUM The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary node | Feb 1, 2018 | 6.5 | 22 | NO | NO |
CVE-2014-9502HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allow remote attackers to hijack | Feb 1, 2018 | 8.8 | 22 | NO | NO |
CVE-2014-9504HIGH The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership | Feb 1, 2018 | 7.5 | 19 | NO | NO |
CVE-2014-8736MEDIUM The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leverag | Nov 12, 2014 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Open Atrium
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.x-2.0 | 3 | 7.6 | 1.3% | 0 | 0 |