Vulnerability from drupal
Published
2024-04-24 13:16
Modified
2025-02-20 18:44
Summary
Details
Progressive web applications are web applications that load like regular web pages or websites but can offer the user functionality such as working offline, push notifications, and device hardware access traditionally available only to native applications.
This module doesn't sufficiently protect access to the settings form, allowing an unauthorized malicious user to view and modify the module settings.
Credits
Andre Groendijk
www.drupal.org/user/3734548
Matthew Grasmick
www.drupal.org/user/455714
{
"affected": [
{
"database_specific": {
"affected_versions": "\u003c1.5.0"
},
"package": {
"ecosystem": "Packagist:https://packages.drupal.org/8",
"name": "drupal/advanced_pwa"
},
"ranges": [
{
"database_specific": {
"constraint": "\u003c1.5.0"
},
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5.0"
}
],
"type": "ECOSYSTEM"
}
],
"severity": []
}
],
"aliases": [
"CVE-2024-13253"
],
"credits": [
{
"contact": [
"https://www.drupal.org/user/3734548"
],
"name": "Andre Groendijk"
},
{
"contact": [
"https://www.drupal.org/user/455714"
],
"name": "Matthew Grasmick"
}
],
"details": "Progressive web applications are web applications that load like regular web pages or websites but can offer the user functionality such as working offline, push notifications, and device hardware access traditionally available only to native applications.\n\nThis module doesn\u0027t sufficiently protect access to the settings form, allowing an unauthorized malicious user to view and modify the module settings.",
"id": "DRUPAL-CONTRIB-2024-017",
"modified": "2025-02-20T18:44:32.000Z",
"published": "2024-04-24T13:16:40.000Z",
"references": [
{
"type": "WEB",
"url": "https://www.drupal.org/sa-contrib-2024-017"
}
],
"schema_version": "1.7.0"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…