CVE-2025-48009: Single Content Sync - Moderately critical - Access bypass - SA-CONTRIB-2025-060
Published May 21, 2025
·Updated
Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.
Affected Software
2 affected components
Drupal Single Content Sync>0.0.0, <1.4.12
Single Content Sync Project Single Content Sync<1.4.12
Event History
May 21, 2025
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-48009?
CVE-2025-48009 is classified as a moderate-severity vulnerability due to its potential for functionality misuse.
2
How do I fix CVE-2025-48009?
To fix CVE-2025-48009, update your Drupal Single Content Sync to version 1.4.12 or later.
3
What systems are affected by CVE-2025-48009?
CVE-2025-48009 affects Drupal Single Content Sync versions from 0.0.0 up to but not including 1.4.12.
4
What type of vulnerability is CVE-2025-48009?
CVE-2025-48009 is a Missing Authorization vulnerability that allows for potential functionality misuse.
5
Who is responsible for Drupal Single Content Sync?
Drupal Single Content Sync is developed and maintained by the Drupal community.