First published: Mon Mar 31 2025(Updated: )
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing. This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open Social | >0.0.0<12.3.11>12.4.0<12.4.10 | |
composer/goalgorilla/open_social | >=12.4.0<12.4.10 | 12.4.10 |
composer/goalgorilla/open_social | <12.3.11 | 12.3.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31686 is considered a critical vulnerability due to its potential for unauthorized access and forceful browsing.
To fix CVE-2025-31686, upgrade your Drupal Open Social instance to versions 12.4.10 or 12.3.11 and above.
CVE-2025-31686 affects Drupal Open Social versions prior to 12.3.11 and versions between 12.4.0 and 12.4.10.
The potential consequences of CVE-2025-31686 include unauthorized access to user accounts and sensitive information through forceful browsing.
Website administrators and developers using affected versions of Drupal Open Social are responsible for addressing CVE-2025-31686 by applying the necessary updates.