Junglewise Threat Intelligence

CVE-2025-3131: DRUPAL-CONTRIB-2025-031 - This module enables you to define automations on your Drupal site. The module doesn't sufficiently protect certain routes from CSRF attacks

CVE-2025-3131 · Severity: info · Published 2025-04-09

Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module enables you to define automations on your Drupal site.

The module doesn't sufficiently protect certain routes from CSRF attacks.

This vulnerability can be mitigated by disabling the "eca\_ui" submodule, which leaves ECA functionality intact, but the vulnerable routes will no longer be available.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/eca

Related threats