Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages: from 0.0.0 before 2.18.0.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-093 |
|
History
Thu, 21 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Config Pages Project
Config Pages Project config Pages |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:config_pages_project:config_pages:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Config Pages Project
Config Pages Project config Pages |
Sat, 16 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal drupal |
|
| Vendors & Products |
Drupal
Drupal drupal |
Fri, 15 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 15 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages: from 0.0.0 before 2.18.0. | |
| Title | Config Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-093 | |
| Weaknesses | CWE-962 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published: 2025-08-15T16:26:46.012Z
Updated: 2025-08-15T18:01:18.736Z
Reserved: 2025-07-30T16:03:41.028Z
Link: CVE-2025-8361
Updated: 2025-08-15T18:01:07.424Z
Status : Analyzed
Published: 2025-08-15T17:15:33.350
Modified: 2025-08-21T18:29:42.840
Link: CVE-2025-8361
No data.