PT-2024-10359 · Drupal · Open Social

·

CVE-2024-13240

·

Published

2024-01-24

·

Updated

2025-01-10

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Social versions 0.0.0 through 12.04
Description The issue is related to improper access control in Drupal Open Social, allowing the collection of data from common resource locations. This can be exploited by a remote attacker to bypass security restrictions.
Recommendations For Open Social versions 0.0.0 through 12.04, update to a version later than 12.04 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00863
CVE-2024-13240
DRUPAL-CONTRIB-2024-004

Affected Products

Open Social