CVE-2024-13259: Image Sizes - Moderately critical - Access bypass - SA-CONTRIB-2024-023
Published Jan 9, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.
Affected Software
2 affected components
Drupal Image Sizes>0.0.0, <3.0.2
Image Sizes Project Image Sizes Drupal<3.0.2
Event History
Jan 9, 2025
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13259?
CVE-2024-13259 has a medium severity rating due to the risk of sensitive information exposure.
2
How do I fix CVE-2024-13259?
To fix CVE-2024-13259, update the Drupal Image Sizes module to version 3.0.2 or later.
3
What versions of Drupal Image Sizes are affected by CVE-2024-13259?
CVE-2024-13259 affects Drupal Image Sizes from version 0.0.0 up to but not including 3.0.2.
4
What is the nature of the vulnerability in CVE-2024-13259?
CVE-2024-13259 is an Insertion of Sensitive Information Into Sent Data vulnerability allowing for forceful browsing.
5
Is there a known exploit for CVE-2024-13259?
As of now, there are no specific details regarding a known exploit for CVE-2024-13259, but the vulnerability should be addressed promptly.