PT-2024-10080 · Drupal · Open Social

Corn696

+2

·

Published

2024-12-11

·

Updated

2025-01-10

·

CVE-2024-13312

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Open Social versions 11.8.0 through 12.3.10 Open Social versions 12.4.0 through 12.4.9
Description The issue is related to a lack of authorization in Drupal Open Social, which allows forceful browsing. This problem can be exploited by a remote attacker to bypass security restrictions and perform a forceful browsing attack.
Recommendations For versions 11.8.0 through 12.3.10, update to a version after 12.3.10 to resolve the issue. For versions 12.4.0 through 12.4.9, update to a version after 12.4.9 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of Open Social to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00253
CVE-2024-13312
DRUPAL-CONTRIB-2024-076

Affected Products

Open Social