PT-2025-13844 · Drupal+1 · Drupal+1

Florent Torregrosa

·

Published

2025-03-31

·

Updated

2025-06-03

·

CVE-2025-31680

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Matomo Analytics versions 0.0.0 through 1.23.0
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics, allowing unauthorized actions to be performed on behalf of a user.
Recommendations For versions 0.0.0 through 1.23.0, update to version 1.24.0 or later to resolve the issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-31680
DRUPAL-CONTRIB-2025-008
GHSA-JH66-RJX8-8QQC

Affected Products

Drupal
Matomo Analytics