Cross-Site Request Forgery Vulnerability in Drupal POST File
CVE-2024-13293
Currently unrated
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Drupal POST File module, allowing unauthorized commands to be transmitted from a user that the web application trusts. This security issue impacts the POST File versions between 0.0.0 before 1.0.2, posing significant risks for web applications that utilize this module. Attackers could exploit this vulnerability to execute actions without the user's consent, potentially leading to unauthorized data manipulation or exposure.
References
Timeline
Vulnerability published