We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-3475

WEB-T - Moderately critical - Access bypass, Denial of service - SA-CONTRIB-2025-030



Description

Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoofing.This issue affects WEB-T: from 0.0.0 before 1.1.0.

Reserved 2025-04-09 | Published 2025-04-09 | Updated 2025-04-09 | Assigner drupal

Problem types

CWE-770 Allocation of Resources Without Limits or Throttling

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

0.0.0 before 1.1.0
affected

Credits

Jan Kellermann (jan kellermann) finder

dragels remediation developer

Jan Kellermann (jan kellermann) remediation developer

Greg Knaddison (greggles) coordinator

Juraj Nemec (poker10) coordinator

References

www.drupal.org/sa-contrib-2025-030

cve.org (CVE-2025-3475)

nvd.nist.gov (CVE-2025-3475)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-3475

Support options

Helpdesk Chat, Email, Knowledgebase