Medium severity5.4NVD Advisory· Published Apr 9, 2025· Updated Jun 17, 2026
CVE-2025-3131
CVE-2025-3131
Description
Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*+ 1 more
- (no CPE)range: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*
- (no CPE)range: 0.0.0
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2025-031nvdVendor Advisory
News mentions
0No linked articles in our index yet.