CVE-2024-13281: Monster Menus - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-045
Published Jan 9, 2025
·Updated
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.
Affected Software
3 affected components
Drupal Monster Menus>undefined
Monster Menus Project Monster Menus Drupal<7.x-1.34
Monster Menus Project Monster Menus Drupal>=9.3.0<9.3.2
Event History
Jan 9, 2025
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13281?
CVE-2024-13281 is classified as a critical vulnerability due to its potential to allow unauthorized access through forceful browsing.
2
How do I fix CVE-2024-13281?
To fix CVE-2024-13281, upgrade Drupal Monster Menus to version 9.3.2 or later.
3
Who is affected by CVE-2024-13281?
CVE-2024-13281 affects all versions of Drupal Monster Menus before 9.3.2.
4
What type of vulnerability is CVE-2024-13281?
CVE-2024-13281 is an Incorrect Authorization vulnerability that can be exploited for forceful browsing.
5
What exploitation risks are associated with CVE-2024-13281?
Exploitation of CVE-2024-13281 could lead to unauthorized users accessing restricted areas of a Drupal site.