Cross-Site Request Forgery Vulnerability in Drupal Minify JS
CVE-2024-13304

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
9 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in Drupal's Minify JS module, enabling attackers to potentially execute unauthorized actions without user consent. This flaw affects all versions prior to 3.0.3, allowing malicious entities to exploit user sessions and perform unintended operations on behalf of the user.

References

Timeline

  • Vulnerability published

.