CVE-2025-3475: WEB-T - Moderately critical - Access bypass, Denial of service - SA-CONTRIB-2025-030
Published Apr 9, 2025
·Updated
Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoofing.This issue affects WEB-T: from 0.0.0 before 1.1.0.
Affected Software
2 affected components
Drupal WEB-T<1.1.0
Europa Web-t Drupal<1.1.0
Event History
Apr 9, 2025
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
May 5, 57258
Event
via FIRST·01:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-3475?
CVE-2025-3475 is considered a medium severity vulnerability due to its impact on resource allocation and potential content spoofing.
2
How do I fix CVE-2025-3475?
To fix CVE-2025-3475, update Drupal WEB-T to version 1.1.0 or later.
3
What types of attacks can exploit CVE-2025-3475?
CVE-2025-3475 can be exploited for excessive resource allocation and content spoofing attacks.
4
Is CVE-2025-3475 present in earlier versions of Drupal WEB-T?
Yes, CVE-2025-3475 affects Drupal WEB-T versions before 1.1.0.
5
What is the main issue caused by CVE-2025-3475?
The main issue caused by CVE-2025-3475 is the allocation of resources without limits or throttling, potentially leading to authorization issues.