PT-2024-10359 · Drupal · Open Social
Corn696
+4
·
Published
2024-01-24
·
Updated
2025-01-10
·
CVE-2024-13240
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open Social versions 0.0.0 through 12.04
Description
The issue is related to improper access control in Drupal Open Social, allowing the collection of data from common resource locations. This can be exploited by a remote attacker to bypass security restrictions.
Recommendations
For Open Social versions 0.0.0 through 12.04, update to a version later than 12.04 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific vulnerability.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Social