CVE-2024-13266: Responsive and off-canvas menu - Moderately critical - Access bypass - SA-CONTRIB-2024-030
Published Jan 9, 2025
·Updated
Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.
Affected Software
2 affected components
Drupal Responsive and off-canvas menu>0.0.0, <4.4.4
Responsive And Off-canvas Menu Project Responsive And Off-canvas Menu Drupal<4.4.4
Event History
Jan 9, 2025
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13266?
The severity of CVE-2024-13266 is categorized as a moderate risk due to incorrect authorization allowing forceful browsing.
2
How do I fix CVE-2024-13266?
To fix CVE-2024-13266, update the Drupal Responsive and off-canvas menu to version 4.4.4 or later.
3
Which versions are affected by CVE-2024-13266?
CVE-2024-13266 affects Drupal Responsive and off-canvas menu versions from 0.0.0 to before 4.4.4.
4
What type of vulnerability is CVE-2024-13266?
CVE-2024-13266 is an Incorrect Authorization vulnerability that may lead to unauthorized access.
5
Is CVE-2024-13266 a zero-day vulnerability?
CVE-2024-13266 is not classified as a zero-day vulnerability since it was publicly disclosed after being identified.