CVE-2024-13244: Migrate Tools - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-008
Published Jan 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.
Affected Software
3 affected components
Drupal Migrate Tools>0.0.0, <6.0.3
Migrate Tools Project Migrate Tools Drupal>=6.0.0<6.0.3
Migrate Tools Project Migrate Tools Drupal>=8.x-1.0<=8.x-5.2
Event History
Jan 9, 2025
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13244?
CVE-2024-13244 is classified as a cross-site request forgery (CSRF) vulnerability that could allow unauthorized actions to be performed.
2
How do I fix CVE-2024-13244?
To mitigate CVE-2024-13244, update the Drupal Migrate Tools to version 6.0.3 or later.
3
Who is affected by CVE-2024-13244?
CVE-2024-13244 affects all versions of Drupal Migrate Tools prior to 6.0.3.
4
What type of vulnerability is CVE-2024-13244?
CVE-2024-13244 is a cross-site request forgery (CSRF) vulnerability.
5
What impact does CVE-2024-13244 have on systems?
CVE-2024-13244 may allow an attacker to perform actions on behalf of an authenticated user without their consent.