Authorization Flaw in Drupal Open Social Affects Multiple Versions
CVE-2024-13312
5.3MEDIUM
Summary
A missing authorization vulnerability in Drupal Open Social permits unauthenticated users to access restricted resources through forceful browsing. This weakness affects specific versions of Open Social, namely from 11.8.0 to 12.3.10 and 12.4.0 to 12.4.9, potentially exposing sensitive functionalities to unauthorized parties. Organizations using these versions should review their configurations and apply necessary updates to safeguard against this risk.
Affected Version(s)
Open Social 11.8.0 < 12.3.10
Open Social 12.4.0 < 12.4.9
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
corn696
corn696
Robert Ragas
Greg Knaddison