CVE-2024-13256: Email Contact Project Email Contact
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.
Affected products
- Email Contact Project Email Contact: before 2.0.4 (fixed in 2.0.4)
Published 2025-01-09. Last modified 2026-06-17.