DRUPAL-CONTRIB-2025-079

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/social/DRUPAL-CONTRIB-2025-079.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2025-079
Aliases
  • CVE-2025-48921
Withdrawn
2026-03-18T18:00:07.435939Z
Published
2025-06-25T18:41:34Z
Modified
2026-03-18T18:00:07.435939Z
Summary
[none]
Details

Open Social is a Drupal distribution for online communities, which ships with a default module that allows users to enroll in events.

The module doesn't sufficiently protect certain routes from Cross Site Request Forgery (CSRF) attacks. Users can be tricked into accepting or rejecting these enrollments.

This issue only affects sites that have event enrollments enabled for an event.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/social

Package

Name
drupal/social
Purl
pkg:composer/drupal/social

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.3.14
Database specific
{
    "constraint": "<12.3.14"
}
Type
ECOSYSTEM
Events
Introduced
12.4.0
Fixed
12.4.13
Database specific
{
    "constraint": ">=12.4.0 <12.4.13"
}

Database specific

affected_versions
"<12.3.14 || >=12.4.0 <12.4.13"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/social/DRUPAL-CONTRIB-2025-079.json"