Drupal Search API Solr Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Drupal Search API Solr module, affecting versions prior to 4.3.9. This vulnerability allows attackers to exploit CSRF by not adequately protecting certain routes, potentially leading to unauthorized actions being performed on behalf of users.

Impact

Exploitation of this vulnerability could allow for Cross-Site Request Forgery attacks, where an attacker could trick a user into performing actions they did not intend to.

Remediation

Users of the Search API Solr module for Drupal 8+ should upgrade to version 4.3.10. It is also recommended to check the Solr configuration for any unintended changes.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.