HomeDrupalCVE-2025-3131

CVE-2025-3131

MEDIUM
5.4CVSS
Published: 2025-04-09
Updated: 2025-04-22
AI Analysis

Description

Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
low
Availability
none
Weaknesses
CWE-352CWE-352

Metadata

Primary Vendor
DRUPAL
Published
4/9/2025
Last Modified
4/22/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

drupal : eca\drupal : eca\drupal : eca\

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-3131 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com