Intel

AIKIDO-2025-10477

drupal/search_api_solr is vulnerable to Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF)CVE-2025-3907 Published Jul 18, 2025

53

Medium Risk

This Affects:

PHPdrupal/search_api_solr
1.0.0 - 4.3.8
Fixed in 4.3.9
Are you affected? Scan for Free

TL;DR

The module doesn't sufficiently protect certain routes from CSRF attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/search_api_solr is vulnerable to Cross-Site Request Forgery (CSRF) in versions 1.0.0 - 4.3.8.

How to fix this

Upgrade the drupal/search_api_solr library to the patch version.