CVE-2024-13282: Block Permissions Project Block Permissions
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.
Affected products
- Block Permissions Project Block Permissions: from 1.0.0, before 1.2.0 (fixed in 1.2.0)
Published 2025-01-09. Last modified 2026-06-17.