{"id":"DRUPAL-CONTRIB-2025-047","details":"The Restrict route by IP module provides an interface to manage route restriction by IP address.\n\nThe module doesn't sufficiently protect certain routes from CSRF attacks.\n\nThis vulnerability is mitigated by the fact that you need to know the route machine name.","aliases":["CVE-2025-47701"],"modified":"2026-09-10T03:45:15.176293837Z","published":"2025-05-07T17:06:16Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-047"}],"affected":[{"package":{"name":"drupal/restrict_route_by_ip","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/restrict_route_by_ip?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0"}],"database_specific":{"constraint":"\u003c1.3.0"}}],"database_specific":{"affected_versions":"\u003c1.3.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/restrict_route_by_ip/DRUPAL-CONTRIB-2025-047.json"}}],"schema_version":"1.9.0","credits":[{"name":"Juraj Nemec (poker10)","contact":["https://www.drupal.org/u/poker10"]}]}