Impact
A Cross‑Site Request Forgery (CSRF) vulnerability is present in the Drupal Salesforce Suite module. The flaw permits a malicious actor to trick an authenticated user into submitting a form or request that the user did not intend, potentially allowing the attacker to perform unauthorized actions on behalf of that user. The weakness is classified as CWE‑352, indicating that the system fails to properly verify the source of requests.
Affected Systems
Drupal sites that include the Salesforce Suite module are at risk. All releases of the module from version 0.0.0 through 5.1.3 contain the CSRF flaw, meaning any site running an affected version is vulnerable.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The CVSS score of 4.8 reflects moderate severity. Likely attack vectors are standard web‑based requests originating from a browser while the user is authenticated, taking advantage of the missing CSRF token to submit actions on the victim’s behalf.
OpenCVE Enrichment