« Volver al listado

CVE-2025-31683

Estado: AnalizadaMedia (6.8)—

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-31683",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-31683",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-29T15:33:33.662040Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "mlhess@drupal.org",
      "affectedData": [
        {
          "repo": "https://git.drupalcode.org/project/google_tag",
          "vendor": "Drupal",
          "product": "Google Tag",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "1.8.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.0.8",
              "versionType": "semver"
            }
          ],
          "collectionURL": "https://www.drupal.org/project/google_tag",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-03-31T22:15:20.890",
  "references": [
    {
      "url": "https://www.drupal.org/sa-contrib-2025-012",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mlhess@drupal.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mlhess@drupal.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8."
    },
    {
      "lang": "es",
      "value": "La vulnerabilidad de Cross-Site Request Forgery (CSRF) en Drupal Google Tag permite Cross-Site Request Forgery. Este problema afecta a Google Tag: desde la versión 0.0.0 hasta la 1.8.0, desde la versión 2.0.0 hasta la 2.0.8."
    }
  ],
  "lastModified": "2026-06-17T09:10:46.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google_tag_project:google_tag:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C06F1DD-03BE-43B3-B72B-7AEAC2D4D7E7",
              "versionEndExcluding": "8.x-1.8",
              "versionStartIncluding": "7.x-1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google_tag_project:google_tag:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2653C18-55AA-425B-8E04-F73926BD4F8C",
              "versionEndExcluding": "2.0.8",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mlhess@drupal.org"
}