CVE-2025-31674
Essential information
- Published
- 31/03/2025 22:15
- Modified
- 01/04/2025 20:26
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.
NVD status
- Status
- Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| drupal / drupal | cpe:2.3:a:drupal:drupal:8.0.0-10.3.12:*:*:*:*:*:*:* |
| drupal / drupal | cpe:2.3:a:drupal:drupal:10.4.0-10.4.2:*:*:*:*:*:*:* |
| drupal / drupal | cpe:2.3:a:drupal:drupal:11.0.0-11.0.11:*:*:*:*:*:*:* |
| drupal / drupal | cpe:2.3:a:drupal:drupal:11.1.0-11.1.2:*:*:*:*:*:*:* |