Cross-Site Request Forgery Vulnerability in Drupal POST File
CVE-2024-13293

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
9 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Drupal POST File module, allowing unauthorized commands to be transmitted from a user that the web application trusts. This security issue impacts the POST File versions between 0.0.0 before 1.0.2, posing significant risks for web applications that utilize this module. Attackers could exploit this vulnerability to execute actions without the user's consent, potentially leading to unauthorized data manipulation or exposure.

References

Timeline

  • Vulnerability published

.