Description
Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
0.0.0 (semver) before 1.0.4
Credits
Pierre Rudloff (prudloff)
drdam
Pierre Rudloff (prudloff)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Jess (xjm)
References
www.drupal.org/sa-contrib-2025-086