PT-2024-10361 · Drupal · Drupal Entity Delete Log

Benji Fisher

+5

·

Published

2024-01-31

·

Updated

2025-01-10

·

CVE-2024-13243

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Drupal Entity Delete Log versions 0.0.0 through 1.1.1
Description The issue is related to a lack of authorization in the Drupal Entity Delete Log, which allows for forceful browsing. This can enable a remote attacker to bypass security restrictions and perform a forceful browsing attack.
Recommendations For versions 0.0.0 through 1.1.1, update to a version that includes the fix for this issue to prevent forceful browsing attacks. As a temporary workaround, consider restricting access to the Entity Delete Log module until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-00865
CVE-2024-13243
DRUPAL-CONTRIB-2024-007

Affected Products

Drupal Entity Delete Log