Executive brief
The CSS Usage Analyzer module for Drupal is a tool that allows frontend scanners to submit CSS-usage statistics to be displayed in admin reports. The module fails to properly validate or restrict submissions to its `/css-usage-analyzer/save` endpoint, allowing attackers to forge or replay measurements and potentially corrupt analytics data or manipulate site statistics.
Technical details
This is an improper access control vulnerability in the CSS Usage Analyzer module's `/css-usage-analyzer/save` endpoint, which does not sufficiently validate incoming requests against forged or repeated submissions. The endpoint is likely unauthenticated or insufficiently protected, allowing an attacker with network access to POST arbitrary or replayed measurement data. A successful exploit can lead to injection of false CSS-usage metrics, data integrity issues in reports, or potential denial-of-service through repeated submissions.
Affected products
- Drupal CSS Usage Analyzer 1.0.0 to 1.0.1
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in version 1.0.2