{"id":"CVE-2025-10930","aliases":["GHSA-27fv-rpgj-4c6m"],"url":"https://o3.security/vulnerability/CVE-2025-10930","summary":null,"details":"This module allows you to use different currencies on your website and do currency conversion.\n\nThe module doesn't sufficiently protect routes used to enable and disable currencies from Cross-Site Request Forgery (CSRF) attacks, potentially allowing an attacker to trick an admin into changing settings.","published":"2025-09-24T17:27:41Z","modified":"2026-09-10T03:45:14.011028952Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist:https://packages.drupal.org/8","name":"drupal/currency","fixedVersion":"3.5.0"}],"fix":null,"references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-110"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:45:14.011028952Z"}}