CVE-2025-48921
EPSS 0.16%
Description
Open Social is a Drupal distribution for online communities, which ships with a default module that allows users to enroll in events. The module doesn't sufficiently protect certain routes from Cross Site Request Forgery (CSRF) attacks. Users can be tricked into accepting or rejecting these enrollments. This issue only affects sites that have event enrollments enabled for an event.
How to fix CVE-2025-48921
To remediate CVE-2025-48921, upgrade the affected package to a fixed version below.
- Packagist/drupal/social—upgrade to 12.3.14 or later
Is CVE-2025-48921 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 12.3.14 | >= 12.4.0, < 12.4.13