Executive brief
The Project Browser module for Drupal allows administrators to apply recipes and enable modules via a web interface. The module fails to validate requests sufficiently, allowing attackers to trick administrators into performing unwanted actions like enabling malicious modules or applying recipes. An attacker could trick an admin into clicking a malicious link, resulting in unauthorized system modifications.
Technical details
Cross-site request forgery (CSRF) vulnerability in the Project Browser module due to insufficient validation of admin actions. An unauthenticated attacker can craft a malicious request that, when visited by a logged-in admin, executes unwanted module installations or recipe applications. No user interaction beyond normal site browsing is required beyond the admin being authenticated.
Affected products
- Drupal Project Browser <2.0.3 and >=2.1.0 <2.1.5
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in versions 2.0.3 and 2.1.5