PT-2024-10480 · Drupal · Node Export

·

CVE-2024-13295

·

Published

2024-11-20

·

Updated

2025-01-10

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Drupal Node export versions 7.X-* through 7.X-3.2
Description The issue is related to the deserialization of untrusted data in the Node export module of the Drupal CMS, which can lead to object injection. This allows a remote attacker to execute arbitrary code. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. The vulnerability is related to the Node export module and can be exploited through the deserialization mechanism.
Recommendations For versions 7.X-* through 7.X-3.2, update to version 7.X-3.3 or later to resolve the issue. As a temporary workaround, consider disabling the Node export module until a patch is available. Restrict access to the Node export functionality to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01030
CVE-2024-13295

Affected Products

Node Export