PT-2024-10363 · Acquia · Acquia Dam

Balázs Ertl-Bakos

+3

·

Published

2024-06-05

·

Updated

2025-08-27

·

CVE-2024-13261

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Acquia DAM versions 0.0.0 through 1.0.12 Acquia DAM versions 1.1.0 through 1.1.0-beta2
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability in the Acquia DAM module of the Drupal CMS system. This vulnerability can be exploited by a remote attacker to perform a CSRF attack or cause a denial of service.
Recommendations For Acquia DAM versions 0.0.0 through 1.0.12, update to version 1.0.13 or later. For Acquia DAM versions 1.1.0 through 1.1.0-beta2, update to version 1.1.0-beta3 or later. As a temporary workaround, consider restricting access to the Acquia DAM module to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-00867
CVE-2024-13261
DRUPAL-CONTRIB-2024-025

Affected Products

Acquia Dam