Home

Description

Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.

PUBLISHED Reserved 2025-01-09 | Published 2025-01-09 | Updated 2025-01-10 | Assigner drupal

Problem types

CWE-284 Improper Access Control

Product status

Default status
unaffected

0.0.0 (semver) before 12.05
affected

Credits

Corn696 finder

Corn696 remediation developer

Tiago Siqueira remediation developer

Robert Ragas remediation developer

Damien McKenna coordinator

Greg Knaddison coordinator

References

www.drupal.org/sa-contrib-2024-004

cve.org (CVE-2024-13240)

nvd.nist.gov (CVE-2024-13240)

Download JSON