First published: Thu Jan 09 2025(Updated: )
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | >0.0.0<3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13259 has a medium severity rating due to the risk of sensitive information exposure.
To fix CVE-2024-13259, update the Drupal Image Sizes module to version 3.0.2 or later.
CVE-2024-13259 affects Drupal Image Sizes from version 0.0.0 up to but not including 3.0.2.
CVE-2024-13259 is an Insertion of Sensitive Information Into Sent Data vulnerability allowing for forceful browsing.
As of now, there are no specific details regarding a known exploit for CVE-2024-13259, but the vulnerability should be addressed promptly.