CVE-2025-3131

Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*.
References
Link Resource
https://www.drupal.org/sa-contrib-2025-031 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drupal:eca\:event_-_condition_-_action:*:*:*:*:*:drupal:*:*
cpe:2.3:a:drupal:eca\:event_-_condition_-_action:*:*:*:*:*:drupal:*:*
cpe:2.3:a:drupal:eca\:event_-_condition_-_action:*:*:*:*:*:drupal:*:*

History

22 Apr 2025, 16:16

Type Values Removed Values Added
CPE cpe:2.3:a:drupal:eca\:event_-_condition_-_action:*:*:*:*:*:drupal:*:*
References () https://www.drupal.org/sa-contrib-2025-031 - () https://www.drupal.org/sa-contrib-2025-031 - Vendor Advisory
Summary
  • (es) La vulnerabilidad de Cross-Site Request Forgery (CSRF) en Drupal ECA: Event - Condition - Action permite Cross-Site Request Forgery. Este problema afecta a ECA: Evento - Condición - Acción: desde 0.0.0 antes de 1.1.12, desde 2.0.0 antes de 2.0.16, desde 2.1.0 antes de 2.1.7, desde 0.0.0 antes de 1.2.*.
First Time Drupal eca\
Drupal

09 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

09 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-09 18:15

Updated : 2025-04-22 16:16


NVD link : CVE-2025-3131

Mitre link : CVE-2025-3131

CVE.ORG link : CVE-2025-3131


JSON object : View

Products Affected

drupal

  • eca\
CWE
CWE-352

Cross-Site Request Forgery (CSRF)