Description
The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions.
Remediation
References
Related Vulnerabilities
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-2891)
WordPress Plugin Nextend Facebook Connect Unspecified Vulnerability (1.5.7)
WordPress Plugin VO Store Locator-WP Store Locator Unspecified Vulnerability (3.2.14)
MediaWiki Incorrect Authorization Vulnerability (CVE-2023-22945)