CVE-2025-31683: Google Tag - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-012
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery. This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31683?
CVE-2025-31683 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability in the Drupal Google Tag module.
How do I fix CVE-2025-31683?
To mitigate CVE-2025-31683, update the Drupal Google Tag module to version 1.8.0 or later, or version 2.0.8 or later.
What versions of Drupal Google Tag are affected by CVE-2025-31683?
CVE-2025-31683 affects Drupal Google Tag versions before 1.8.0 and versions between 2.0.0 and 2.0.8.
What types of attacks can CVE-2025-31683 enable?
CVE-2025-31683 can enable attackers to perform actions on behalf of authenticated users without their consent.
Is there any workaround for CVE-2025-31683 if I can't update immediately?
While the best solution is to update the module, temporarily restricting access to functionality that is vulnerable can serve as a workaround until an update can be applied.