PT-2024-10230 · Drupal · Drupal Mailjet

·

CVE-2024-13296

·

Published

2024-11-20

·

Updated

2025-01-10

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Drupal Mailjet versions 0.0.0 through 4.0.0
Description The issue is related to the deserialization mechanism in the Mailjet module of the Drupal CMS system. It allows for the deserialization of untrusted data, leading to object injection. This can enable a remote attacker to execute arbitrary code.
Recommendations For versions 0.0.0 through 4.0.0, update to version 4.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the deserialization mechanism in the Mailjet module until a patch is available. Restrict access to the Mailjet module to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00570
CVE-2024-13296
DRUPAL-CONTRIB-2024-062

Affected Products

Drupal Mailjet