nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13241 CVE-2024-13241
CRITICAL
Open Social - Moderately critical - Information Disclosure - SA-CONTRIB-2024-005
Record summary
CVE-2024-13241 has a selected CVSS score of 9.1 (critical).
Description
Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Open SocialBrowse Drupal / Open SocialDefault status: unaffected | CVE List | 0.0.0 to < 12.0.5 | affected |
References
2drupal.org
https://www.drupal.org/sa-contrib-2024-005