CVE-2024-13250: Drupal Symfony Mailer Lite - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-014
Published Jan 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.
Affected Software
2 affected components
Drupal Symfony Mailer Lite>0.0.0, <1.0.6
Drupal Symfony Mailer Lite Project Drupal Symfony Mailer Lite Drupal<1.0.6
Event History
Jan 9, 2025
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13250?
CVE-2024-13250 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-13250?
To fix CVE-2024-13250, update Drupal Symfony Mailer Lite to version 1.0.6 or later.
3
What versions of Drupal Symfony Mailer Lite are affected by CVE-2024-13250?
CVE-2024-13250 affects Drupal Symfony Mailer Lite versions from 0.0.0 up to but not including 1.0.6.
4
Can CVE-2024-13250 be exploited remotely?
Yes, CVE-2024-13250 can be exploited remotely through unauthorized requests.
5
What are the risks associated with CVE-2024-13250?
The risks of CVE-2024-13250 include unauthorized actions being performed on behalf of authenticated users.