PT-2026-82369 · Drupal · Digital Signage Framework
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Digital Signage Framework versions 0.0.0 through 2.6.1
Description
A missing authorization issue allows forceful browsing. The module provides a route for signage devices to refresh dynamic blocks on a display, but it fails to verify if the requester is an authorized signage device or if the requested block is intended for display. Consequently, an anonymous visitor can read the rendered content of blocks they are not authorized to see. This is partially mitigated if block plugins perform their own access checks on the content.
Recommendations
Update Drupal Digital Signage Framework to a version later than 2.6.1.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Digital Signage Framework