Description
Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.
Problem types
Product status
0.0.0 before 2.0.10
3.0.0 before 3.0.1
Credits
Damien McKenna (damienmckenna)
Benji Fisher (benjifisher)
Joris Vercammen (borisson_)
Damien McKenna (damienmckenna)
Thomas Seidl (drunken monkey)
Jimmy Henderickx (strykaizer)
Benji Fisher (benjifisher)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Cathy Theys (yesct)
References
www.drupal.org/sa-contrib-2025-099