Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.
References
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00034}

epss

{'score': 0.0004}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00022}

epss

{'score': 0.00034}


Thu, 10 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
Description Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.
Title Config Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086
Weaknesses CWE-306
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published: 2025-07-08T20:54:28.253Z

Updated: 2025-07-10T14:15:57.161Z

Reserved: 2025-07-02T16:07:06.702Z

Link: CVE-2025-7031

cve-icon Vulnrichment

Updated: 2025-07-10T14:15:38.863Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T21:15:28.907

Modified: 2025-07-10T15:15:30.260

Link: CVE-2025-7031

cve-icon Redhat

No data.