[CIVN-2025-0380] Cross-Site Request Forgery Vulnerability in Acquit Content Hub Module of Drupal

By Published On: December 22, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Cross-Site Request Forgery Vulnerability in Acquit Content Hub Module of Drupal 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: MEDIUM
Software Affected
Acquit Content Hub module for Drupal prior to versions 3.6.4
Acquit Content Hub module for Drupal prior to versions 3.7.3
Overview
A vulnerability has been reported in Acquit Content Hub Module of Drupal which could allow an attacker to conduct cross-site request forgery (CSRF) attacks on the target system.
Target Audience:
Individuals and end-user organizations using Drupal Modules
Risk Assessment:
Moderate risk of unauthorized access to sensitive data
Impact Assessment:
Potential for data theft
Description
Drupal is an open-source, content management system (CMS) which allows individuals and organizations to create, manage and maintain websites and web applications.
This vulnerability exists in the Acquit Content Hub Module’s content export routes due to improper validation of CSRF tokens. An attacker could exploit this vulnerability by inducing an authenticated administrator to trigger a crafted request.
Successful exploitation of this vulnerability could result in unauthorized export and potential disclosure of sensitive content of the target system.
Solution
Upgrade to the latest versions as mentioned in the advisory:
https://www.drupal.org/sa-contrib-2025-125
Vendor Information
Drupal
https://www.drupal.org/
References
 
https://www.drupal.org/sa-contrib-2025-125
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmlJT8AACgkQ3jCgcSdc
ys8ORA//SsluyA+dqJ2Gr6l4ZV1MOtZoCQtzoOUyuR3v1gVWq+2Cqreai2kDIZpZ
2hXsGruKpxCwAB6Rs4Q4T2I2gq/KvF3J4847U0YDFGiMJfX08HVsjGfzPFuKop23
XpldI2kjLPibv+8hQNikZ6HXyMWY+pyd7wttuDh7EPDspMNAoOGBdo5zWZYSuVsD
+8iTpzXu9kBjVXQU7QEZSz1LYKglIdMhUr18QvhFnQurj091MK9SVHuKlics2ONy
qmIs7qiEniwe6+Vz7LBnWaM6mVkZpQL/T8KXEL2RUUG3mN0h3OmWutT9IX6SiLqa
7QjQBN2w2cc5M4F87h7hr2okqs+8RlVQvjY9P/WDDMGxvPIUTEMownlH1jvBI+aB
f2mEkAG8gcGOAE4oli7WcCzaHgvAqaimcV6E0QVm7gJ713RuhmVeZ2mwwJtOdP4C
aJxWYY5xwOVz96rL95BMJV1z9FvS/b3da1nhG/+8Y8l5bbANVXE8oG7vk/fl3ULk
P7gUEMSHaCQVOs29Zle5KRBy2R9uvX72b9/kYebY0Eq7uY2CPamFdEjDCKN/CGzt
Ayja4D0t4GXCCVkCDWZ5p1ZJ42XJHCmkB3TXf5jXTVFOzl4ny3APEx5pE11QEAU4
dEAOLi+mypZgbzmev3mT8NRXf8IssAd3bursWMS2Raa8nbiWrk4=
=tbXN
—–END PGP SIGNATURE—–

Share this article