CVE-2024-13260: Migrate queue importer - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-024
Published Jan 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.
Affected Software
2 affected components
Drupal Migrate queue importer<2.1.1
Migrate Queue Importer Project Migrate Queue Importer Drupal<2.1.1
Event History
Jan 9, 2025
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13260?
CVE-2024-13260 is categorized as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-13260?
To fix CVE-2024-13260, upgrade the Migrate queue importer to version 2.1.1 or later.
3
What software is affected by CVE-2024-13260?
CVE-2024-13260 affects the Drupal Migrate queue importer versions prior to 2.1.1.
4
What type of vulnerability is CVE-2024-13260?
CVE-2024-13260 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
When was CVE-2024-13260 disclosed?
CVE-2024-13260 was disclosed as a security advisory in 2024.