Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-9037 | Drupal Matomo Analytics Cross-Site Request Forgery (CSRF) vulnerability | 
|  Github GHSA | GHSA-jh66-rjx8-8qqc | Drupal Matomo Analytics Cross-Site Request Forgery (CSRF) vulnerability | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://www.drupal.org/sa-contrib-2025-008 |  | 
History
                    Mon, 02 Jun 2025 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Matomo Analytics Project Matomo Analytics Project matomo Analytics | |
| CPEs | cpe:2.3:a:matomo_analytics_project:matomo_analytics:*:*:*:*:*:drupal:*:* | |
| Vendors & Products | Matomo Analytics Project Matomo Analytics Project matomo Analytics | 
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Mon, 31 Mar 2025 21:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0. | |
| Title | Matomo Analytics - Moderately critical - Cross site request forgery - SA-CONTRIB-2025-008 | |
| Weaknesses | CWE-352 | |
| References |  | 
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-04-29T15:38:13.666Z
Reserved: 2025-03-31T21:30:04.616Z
Link: CVE-2025-31680
Updated: 2025-04-29T15:38:02.522Z
Status : Analyzed
Published: 2025-03-31T22:15:20.550
Modified: 2025-06-02T20:00:35.477
Link: CVE-2025-31680
No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.