{"id":"DRUPAL-CONTRIB-2025-079","details":"Open Social is a Drupal distribution for online communities, which ships with a default module that allows users to enroll in events.\n\nThe module doesn't sufficiently protect certain routes from Cross Site Request Forgery (CSRF) attacks. Users can be tricked into accepting or rejecting these enrollments.\n\nThis issue only affects sites that have event enrollments enabled for an event.","aliases":["CVE-2025-48921"],"modified":"2026-03-18T18:00:07.435939Z","published":"2025-06-25T18:41:34Z","withdrawn":"2026-03-18T18:00:07.435939Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-079"}],"affected":[{"package":{"name":"drupal/social","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/social"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.3.14"}],"database_specific":{"constraint":"\u003c12.3.14"}},{"type":"ECOSYSTEM","events":[{"introduced":"12.4.0"},{"fixed":"12.4.13"}],"database_specific":{"constraint":"\u003e=12.4.0 \u003c12.4.13"}}],"database_specific":{"affected_versions":"\u003c12.3.14 || \u003e=12.4.0 \u003c12.4.13","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/social/DRUPAL-CONTRIB-2025-079.json"}}],"schema_version":"1.7.3","credits":[{"name":"Ivo  Van Geertruyen (mr.baileys)","contact":["https://www.drupal.org/u/mrbaileys"]}]}