CVE-2025-3131: ECA: Event - Condition - Action - Critical - Cross site request forgery - SA-CONTRIB-2025-031
Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3131?
The severity of CVE-2025-3131 is classified as high due to its potential for Cross-Site Request Forgery (CSRF) attacks.
How do I fix CVE-2025-3131?
To fix CVE-2025-3131, upgrade to Drupal ECA: Event - Condition - Action version 1.1.12, 2.0.16, or 2.1.7, or any version from 1.2.* onwards.
Which versions of Drupal ECA: Event - Condition - Action are affected by CVE-2025-3131?
CVE-2025-3131 affects versions before 1.1.12, versions before 2.0.16, and versions before 2.1.7, specifically from initial release to these versions.
What is the impact of CVE-2025-3131 on my website?
The impact of CVE-2025-3131 includes potential unauthorized actions performed by an attacker on behalf of a user without their consent.
Is there a workaround for CVE-2025-3131?
There is no documented workaround for CVE-2025-3131, so upgrading to a patched version is recommended to mitigate the vulnerability.