CVE-2024-13255
Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.51%
- CWE
- CWE-202
- Published
- 2025-01-09
- Last modified
- 2026-03-13
Affected products
- Drupal RESTful Web Services
Weakness type
Related vulnerabilities
- CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability...
- CVE-2026-25703 — Potential information leakage from manager /network/graph API in NeuVector
- CVE-2026-70473 — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
- CVE-2026-42797 — Apache Syncope: JexlContextBuilder Information Disclosure
- CVE-2026-40245 — Free5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
- CVE-2026-30778 — Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
- CVE-2026-33530 — InvenTree Vulnerable to ORM Filter Injection
- CVE-2026-3546 — e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action