First published: Mon Mar 31 2025(Updated: )
Incorrect Authorization vulnerability in Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | >=8.0.0<10.3.13>=10.4.0<10.4.3>=11.0.0<11.0.12>=11.1.0<11.1.3 | |
composer/drupal/core | >=11.1.0<11.1.3 | 11.1.3 |
composer/drupal/core | >=11.0.0<11.0.12 | 11.0.12 |
composer/drupal/core | >=10.4.0<10.4.3 | 10.4.3 |
composer/drupal/core | >=8.0.0<10.3.13 | 10.3.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31673 is categorized as a critical severity vulnerability affecting multiple versions of Drupal core.
To resolve CVE-2025-31673, upgrade your Drupal core to version 10.4.3, 11.0.12, or 11.1.3, or later versions.
CVE-2025-31673 affects Drupal core versions from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, and from 11.0.0 before 11.0.12 and 11.1.0 before 11.1.3.
CVE-2025-31673 is an incorrect authorization vulnerability that allows for forceful browsing.
No, CVE-2025-31673 can be exploited without any authentication, making it particularly severe.