Cross-Site Request Forgery Vulnerability in Drupal Search API Solr
CVE-2025-3907

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
23 April 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Drupal Search API Solr module, exposing users to unauthorized actions without their consent. This issue can be exploited by attackers to send malicious requests, potentially compromising user data and system integrity. It is crucial for users of affected versions, particularly those prior to 4.3.9, to be aware of this risk and apply the necessary security measures to safeguard their applications.

Affected Version(s)

Search API Solr 0.0.0 < 4.3.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
Thomas Seidl (drunken monkey)
Markus Kalkbrenner (mkalkbrenner)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
.