Cross-Site Request Forgery Vulnerability in Drupal Open Social
CVE-2025-48921

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
26 June 2025

What is CVE-2025-48921?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Drupal's Open Social. This weakness allows an attacker to trick a user into executing unwanted actions on a web application in which they are authenticated. Specifically, the vulnerability affects versions of Open Social prior to 12.3.14 and 12.4.13, potentially leading to unauthorized commands being transmitted to the application's server. Users and administrators are urged to review their sites and upgrade to the patched versions to mitigate any risks associated with this vulnerability. For detailed information and resolution steps, refer to the official Drupal security advisory.

Affected Version(s)

Open Social 0.0.0 < 12.3.14

Open Social 12.4.0 < 12.4.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivo Van Geertruyen (mr.baileys)
Alexander Varwijk (kingdutch)
Robert Ragas (robertragas)
Greg Knaddison (greggles)
.
CVE-2025-48921 : Cross-Site Request Forgery Vulnerability in Drupal Open Social