CVE-2024-13280: Persistent Login - Moderately critical - Access bypass - SA-CONTRIB-2024-044
Published Jan 9, 2025
·Updated
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0. before 2.2.2.
Affected Software
4 affected components
Drupal Persistent Login>0.0.0, <1.8.0, >=2.0.0, <2.2.2
Persistent Login Project Persistent Login Drupal<1.8.0
Persistent Login Project Persistent Login Drupal>=2.0.0<2.1.1
Persistent Login Project Persistent Login Drupal>=2.2.0<2.2.2
Event History
Jan 9, 2025
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13280?
CVE-2024-13280 is categorized as a moderate severity vulnerability due to its potential for forceful browsing attacks.
2
How do I fix CVE-2024-13280?
To fix CVE-2024-13280, upgrade Drupal Persistent Login to version 1.8.0 or 2.2.2 or higher.
3
What software versions are affected by CVE-2024-13280?
CVE-2024-13280 affects Drupal Persistent Login versions prior to 1.8.0 and 2.0.* versions before 2.2.2.
4
What type of vulnerability is CVE-2024-13280?
CVE-2024-13280 is an Insufficient Session Expiration vulnerability, allowing unauthorized access during active sessions.
5
Can CVE-2024-13280 be exploited remotely?
Yes, CVE-2024-13280 can potentially be exploited remotely through forceful browsing techniques.