PT-2024-10347 · Drupal · Email Contact

·

CVE-2024-13256

·

Published

2024-05-22

·

Updated

2025-01-10

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Email Contact versions 0.0.0 through 2.0.4
Description The issue is related to insufficient granularity of access control in the Email Contact module for Drupal, allowing forceful browsing. This can be exploited by a remote attacker to bypass security restrictions.
Recommendations For versions 0.0.0 through 2.0.4, update to a version newer than 2.0.4 to resolve the issue. As a temporary workaround, consider restricting access to the Email Contact module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00847
CVE-2024-13256
DRUPAL-CONTRIB-2024-020

Affected Products

Email Contact