PT-2024-10084 · Drupal+1 · Drupal+1

Pierre Rudloff

+1

·

Published

2024-12-04

·

Updated

2025-01-10

·

CVE-2024-13304

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Minify JS versions 0.0.0 through 3.0.3
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability in the Minify JS module of the Drupal CMS system. This vulnerability can be exploited by a remote attacker to perform a CSRF attack.
Recommendations For versions 0.0.0 through 3.0.3, update to a version 3.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Minify JS module to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-00258
CVE-2024-13304
DRUPAL-CONTRIB-2024-070

Affected Products

Drupal
Minify Js