CVE-2025-48921
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-06-26

Last updated on: 2025-07-09

Assigner: Drupal.org

Description
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.14, from 12.4.0 before 12.4.13.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-06-26
Last Modified
2025-07-09
Generated
2026-05-07
AI Q&A
2025-06-26
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
getopensocial open_social to 12.3.14 (exc)
getopensocial open_social From 12.4.0 (inc) to 12.4.13 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the Drupal Open Social distribution. It occurs because the default event enrollment module does not properly protect certain routes against CSRF attacks. This means that an attacker could trick a user into unintentionally accepting or rejecting event enrollments without their consent. It affects Open Social versions before 12.3.14 and versions from 12.4.0 before 12.4.13, and only impacts sites with event enrollments enabled. [1]


How can this vulnerability impact me? :

The vulnerability can impact you by allowing attackers to manipulate event enrollments on your site without your knowledge or consent. This could lead to unauthorized changes in event participation, potentially disrupting community activities or causing confusion. Since it affects integrity to some extent, it may undermine trust in the event management functionality of your site. [1]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

This vulnerability affects Open Social versions before 12.3.14 and from 12.4.0 before 12.4.13 with event enrollments enabled. Detection involves verifying the Open Social version in use and whether the event enrollment module is enabled. There are no specific commands provided to detect exploitation or presence of this vulnerability on your network or system. [1]


What immediate steps should I take to mitigate this vulnerability?

The recommended immediate mitigation is to upgrade Open Social to version 12.3.14 if using the 12.3.x branch, or to version 12.4.13 if using the 12.4.x branch. This will apply the fix for the CSRF vulnerability in the event enrollment module. Additionally, if event enrollments are not needed, consider disabling that feature to reduce exposure. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart