CVE-2025-8361: Config Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-093
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.
This issue affects Config Pages: from 0.0.0 before 2.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Config Pagesto a version that resolves this vulnerability.Fixed in 2.18.0Patch SA-CONTRIB-2025-093
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8361?
CVE-2025-8361 is considered a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-8361?
To fix CVE-2025-8361, upgrade Drupal Config Pages to version 2.18.0 or later.
What causes CVE-2025-8361?
CVE-2025-8361 is caused by a missing authorization check in the configuration page functionality of Drupal.
Who is affected by CVE-2025-8361?
Any Drupal site utilizing Config Pages versions prior to 2.18.0 is potentially affected by CVE-2025-8361.
What are the potential impacts of CVE-2025-8361?
The potential impacts of CVE-2025-8361 include unauthorized access to sensitive configuration settings.