Project: 
Date: 
2025-February-12
Vulnerability: 
Access bypass, Information Disclosure
Affected versions: 
<12.3.11 || >=12.4.0 <12.4.10
CVE IDs: 
CVE-2025-31686
Description: 

Open Social is a Drupal distribution for online communities, which ships with a default module to invite users to groups and events.

Invites for a specific user can be seen under certain conditions.

The issue is mitigated for events by the fact that social_event_max_enroll has to be enabled.

Solution: 

Install the latest version:

Coordinated By: