PT-2024-10480 · Drupal · Node Export

Drew Webber

+2

·

Published

2024-11-20

·

Updated

2025-01-10

·

CVE-2024-13295

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Drupal Node export versions 7.X-* through 7.X-3.2
Description The issue is related to the deserialization of untrusted data in the Node export module of the Drupal CMS, which can lead to object injection. This allows a remote attacker to execute arbitrary code. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. The vulnerability is related to the Node export module and can be exploited through the deserialization mechanism.
Recommendations For versions 7.X-* through 7.X-3.2, update to version 7.X-3.3 or later to resolve the issue. As a temporary workaround, consider disabling the Node export module until a patch is available. Restrict access to the Node export functionality to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-01030
CVE-2024-13295

Affected Products

Node Export