VDB
Sign up
—

DRUPAL-CONTRIB-2021-040

Details

This module provides an admin interface for creating drop down menus that combine Drupal menu items with rich media content.

The module does not use CSRF tokens to protect routes for saving menu configurations.

This vulnerability can be exploited by an anonymous user.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/tb_megamenu
Introduced in: 0Fixed in: 1.4.0

Upgrade drupal/tb_megamenu to 1.4.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References