Description
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages: from 0.0.0 before 2.18.0.
Problem types
Product status
0.0.0 before 2.18.0
Credits
Pierre Rudloff (prudloff)
Pierre Rudloff (prudloff)
Alexander Shumenko (shumer)
Greg Knaddison (greggles)
Heine Deelstra (heine)
Jess (xjm)
References
www.drupal.org/sa-contrib-2025-093