First published: Mon Mar 31 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery. This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Google Tag | >0.0.0<1.8.0>2.0.0<2.0.8 | |
composer/drupal/google_tag | >=2.0.0<2.0.8 | 2.0.8 |
composer/drupal/google_tag | <1.8.0 | 1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31683 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability in the Drupal Google Tag module.
To mitigate CVE-2025-31683, update the Drupal Google Tag module to version 1.8.0 or later, or version 2.0.8 or later.
CVE-2025-31683 affects Drupal Google Tag versions before 1.8.0 and versions between 2.0.0 and 2.0.8.
CVE-2025-31683 can enable attackers to perform actions on behalf of authenticated users without their consent.
While the best solution is to update the module, temporarily restricting access to functionality that is vulnerable can serve as a workaround until an update can be applied.