PT-2024-10347 · Drupal · Email Contact
Bálint Nagy
+3
·
Published
2024-05-22
·
Updated
2025-01-10
·
CVE-2024-13256
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Email Contact versions 0.0.0 through 2.0.4
Description
The issue is related to insufficient granularity of access control in the Email Contact module for Drupal, allowing forceful browsing. This can be exploited by a remote attacker to bypass security restrictions.
Recommendations
For versions 0.0.0 through 2.0.4, update to a version newer than 2.0.4 to resolve the issue.
As a temporary workaround, consider restricting access to the Email Contact module to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Email Contact