{"id":"DRUPAL-CONTRIB-2024-008","details":"The Migrate Tools module provides tools for running and managing Drupal migrations.\n\nThe module doesn't sufficiently protect against Cross Site Request Forgery under specific scenarios allowing an attacker to trick an authenticated administrator into initiating a migration.\n\nThis vulnerability is mitigated by the fact that an attacker must know the name of the migration.","aliases":["CVE-2024-13244"],"modified":"2026-09-10T03:45:59.021905026Z","published":"2024-02-07T17:56:55Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2024-008"}],"affected":[{"package":{"name":"drupal/migrate_tools","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/migrate_tools?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3"}],"database_specific":{"constraint":"\u003c6.0.3"}}],"database_specific":{"affected_versions":"\u003c6.0.3","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/migrate_tools/DRUPAL-CONTRIB-2024-008.json"}}],"schema_version":"1.9.0","credits":[{"name":"Andreas Hennings","contact":["https://www.drupal.org/user/459338"]}]}