PT-2024-10478 · Drupal+1 · Drupal+1

·

CVE-2024-13293

·

Published

2024-11-13

·

Updated

2025-01-10

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal POST File versions 0.0.0 through 1.0.2
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability in the POST File module of the Drupal CMS system. This vulnerability can be exploited by a remote attacker to perform a CSRF attack, allowing for unauthorized actions on the affected system.
Recommendations For versions 0.0.0 through 1.0.2, update to a version later than 1.0.2 to resolve the issue. As a temporary workaround, consider restricting access to the POST File module until a patch is available. Avoid using the POST File module in sensitive operations until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01028
CVE-2024-13293
DRUPAL-CONTRIB-2024-059

Affected Products

Drupal
Post File