{"id":"DRUPAL-CONTRIB-2021-040","details":"This module provides an admin interface for creating drop down menus that combine Drupal menu items with rich media content.\n\nThe module does not use CSRF tokens to protect routes for saving menu configurations.\n\nThis vulnerability can be exploited by an anonymous user.","modified":"2026-09-10T03:46:05.494785946Z","published":"2021-09-22T17:26:12Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2021-040"}],"affected":[{"package":{"name":"drupal/tb_megamenu","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/tb_megamenu?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.0"}],"database_specific":{"constraint":"\u003c1.4.0"}}],"database_specific":{"affected_versions":"\u003c1.4.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/tb_megamenu/DRUPAL-CONTRIB-2021-040.json"}}],"schema_version":"1.9.0","credits":[{"name":"Patrick Fey","contact":["https://www.drupal.org/user/998680"]}]}