CVE-2024-13240

Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.
References
Link Resource
https://www.drupal.org/sa-contrib-2024-004 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:getopensocial:open_social:*:*:*:*:*:drupal:*:*

History

04 Jun 2025, 16:41

Type Values Removed Values Added
References () https://www.drupal.org/sa-contrib-2024-004 - () https://www.drupal.org/sa-contrib-2024-004 - Vendor Advisory
CPE cpe:2.3:a:getopensocial:open_social:*:*:*:*:*:drupal:*:*
First Time Getopensocial
Getopensocial open Social
CWE NVD-CWE-noinfo

10 Jan 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Una vulnerabilidad de control de acceso inadecuado en Drupal Open Social permite recopilar datos de ubicaciones de recursos comunes. Este problema afecta a Open Social: desde la versión 0.0.0 hasta la 12.05.

09 Jan 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 19:15

Updated : 2025-06-04 16:41


NVD link : CVE-2024-13240

Mitre link : CVE-2024-13240

CVE.ORG link : CVE-2024-13240


JSON object : View

Products Affected

getopensocial

  • open_social
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo