216.73.217.22

CVE-2025-31674

· Published 31/03/2025 22:15 · Modified 01/04/2025 20:26

Labels: CVE-2025-31674 2025-03-31CVE-2025-31674CWE-915[email protected]

Essential information

Published
31/03/2025 22:15
Modified
01/04/2025 20:26
Author
Creator
CISA KEV
No
CWE

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
drupal / drupal cpe:2.3:a:drupal:drupal:8.0.0-10.3.12:*:*:*:*:*:*:*
drupal / drupal cpe:2.3:a:drupal:drupal:10.4.0-10.4.2:*:*:*:*:*:*:*
drupal / drupal cpe:2.3:a:drupal:drupal:11.0.0-11.0.11:*:*:*:*:*:*:*
drupal / drupal cpe:2.3:a:drupal:drupal:11.1.0-11.1.2:*:*:*:*:*:*:*

References