PT-2024-10347 · Drupal · Email Contact

Bálint Nagy

+3

·

Published

2024-05-22

·

Updated

2025-01-10

·

CVE-2024-13256

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Email Contact versions 0.0.0 through 2.0.4
Description The issue is related to insufficient granularity of access control in the Email Contact module for Drupal, allowing forceful browsing. This can be exploited by a remote attacker to bypass security restrictions.
Recommendations For versions 0.0.0 through 2.0.4, update to a version newer than 2.0.4 to resolve the issue. As a temporary workaround, consider restricting access to the Email Contact module to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-00847
CVE-2024-13256
DRUPAL-CONTRIB-2024-020

Affected Products

Email Contact