CVE-2024-13293: POST File - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-059
Published Jan 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects POST File: from 0.0.0 before 1.0.2.
Affected Software
2 affected components
Drupal POST File>0.0.0<=1.0.2
Post File Project Post File Drupal<1.0.2
Event History
Jan 9, 2025
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13293?
CVE-2024-13293 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-13293?
To fix CVE-2024-13293, upgrade to POST File version 1.0.2 or later.
3
Which versions of Drupal POST File are affected by CVE-2024-13293?
CVE-2024-13293 affects Drupal POST File versions from 0.0.0 up to, but not including, 1.0.2.
4
What impact does CVE-2024-13293 have?
CVE-2024-13293 could allow attackers to perform unauthorized actions on behalf of users without their consent.
5
Is CVE-2024-13293 an exploitation risk for existing Drupal installations?
Yes, if your Drupal installation uses affected versions of POST File, it is at risk for exploitation due to CVE-2024-13293.