Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pamela Barone

#28528of 53,632
9Total CVSS
Vulnerabilities · 1
PT-2024-10099
9.0
2024-03-06
Drupal · Drupal Registration Role · CVE-2024-13251
**Name of the Vulnerable Software and Affected Versions** Drupal Registration role versions 0.0.0 through 2.0.0 **Description** The issue is related to an Incorrect Privilege Assignment vulnerability in the Drupal Registration role, which allows for Privilege Escalation. This vulnerability can be exploited by a remote attacker to bypass security restrictions and elevate their privileges. **Recommendations** For versions 0.0.0 through 2.0.0, update to version 2.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Registration role to minimize the risk of exploitation.