—
DRUPAL-CONTRIB-2025-031
Details
This module enables you to define automations on your Drupal site.
The module doesn't sufficiently protect certain routes from CSRF attacks.
This vulnerability can be mitigated by disabling the "eca\_ui" submodule, which leaves ECA functionality intact, but the vulnerable routes will no longer be available.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/eca
Introduced in:
0Fixed in: 1.1.12Upgrade drupal/eca to 1.1.12 or newer (ecosystem packagist:https://packages.drupal.org/8).