Description

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List0.0.0 to < 12.3.11affected
12.4.0 to < 12.4.10affected
GitHub AdvisoryBefore 12.3.11 · Fixed in 12.3.11affected
12.4.0 to < 12.4.10 · Fixed in 12.4.10affected

References

5