PT-2024-10359 · Drupal · Open Social

Corn696

+4

·

Published

2024-01-24

·

Updated

2025-01-10

·

CVE-2024-13240

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Social versions 0.0.0 through 12.04
Description The issue is related to improper access control in Drupal Open Social, allowing the collection of data from common resource locations. This can be exploited by a remote attacker to bypass security restrictions.
Recommendations For Open Social versions 0.0.0 through 12.04, update to a version later than 12.04 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-00863
CVE-2024-13240
DRUPAL-CONTRIB-2024-004

Affected Products

Open Social