Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Markus Kalkbrenner

#18741of 53,632
14.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-17661
4.3
2025-04-23
Drupal · Drupal Search Api Solr · CVE-2025-3907
**Name of the Vulnerable Software and Affected Versions** Drupal Search API Solr versions 0.0.0 through 4.3.8 **Description** A Cross-Site Request Forgery (CSRF) issue affects the software, allowing unauthorized actions to be performed. This issue can be exploited to perform actions on behalf of another user without their knowledge or consent. **Recommendations** For versions 0.0.0 through 4.3.8, update to version 4.3.9 or later to resolve the issue.
PT-2025-2098
10
2024-10-02
Drupal · Drupal Facets · CVE-2024-13283
**Name of the Vulnerable Software and Affected Versions** Drupal Facets versions 0.0.0 through 2.0.9 **Description** The issue is related to improper neutralization of input during web page generation, which allows Cross-Site Scripting (XSS). This can be exploited by a remote attacker to hijack a user's session. The problem is associated with the two-factor authentication module and incorrect session management. **Recommendations** For versions 0.0.0 through 2.0.9, update to a version later than 2.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the Facets module to minimize the risk of exploitation. Avoid using the Facets module until the issue is resolved.