CVE-2014-8736: Open Atrium Project Open Atrium

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node.

Affected products

Published 2014-11-12. Last modified 2026-06-17.