This Open Social distribution provides a turn-key system for building customized social networks.
The module doesn't sufficiently process data in certain circumstances.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access mentions".