PT-2024-10230 · Drupal · Drupal Mailjet

Bohdan Artemchuk

+1

·

Published

2024-11-20

·

Updated

2025-01-10

·

CVE-2024-13296

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Drupal Mailjet versions 0.0.0 through 4.0.0
Description The issue is related to the deserialization mechanism in the Mailjet module of the Drupal CMS system. It allows for the deserialization of untrusted data, leading to object injection. This can enable a remote attacker to execute arbitrary code.
Recommendations For versions 0.0.0 through 4.0.0, update to version 4.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the deserialization mechanism in the Mailjet module until a patch is available. Restrict access to the Mailjet module to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-00570
CVE-2024-13296
DRUPAL-CONTRIB-2024-062

Affected Products

Drupal Mailjet