CVE-2014-8736: Open Atrium Project Open Atrium
Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.
The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node.
Affected products
- Open Atrium Project Open Atrium: up to and including 7.x-2.21
Published 2014-11-12. Last modified 2026-06-17.