PT-2024-10356 · Drupal · Drupal Paragraphs Table

Greg Knaddison

+6

·

Published

2024-09-04

·

Updated

2025-08-27

·

CVE-2024-13272

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal Paragraphs table versions 0.0.0 through 1.22.0 Drupal Paragraphs table versions 2.0.0 through 2.0.1
Description The issue is related to insufficient granularity of access control in Drupal Paragraphs table, which allows content spoofing. This can be exploited by a remote attacker to bypass security restrictions and gain unauthorized access to protected information.
Recommendations For Drupal Paragraphs table versions 0.0.0 through 1.22.0, update to version 1.23.0 or later. For Drupal Paragraphs table versions 2.0.0 through 2.0.1, update to version 2.0.2 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-00859
CVE-2024-13272
DRUPAL-CONTRIB-2024-036

Affected Products

Drupal Paragraphs Table