Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.
References
History

Thu, 04 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Config Pages Viewer Project
Config Pages Viewer Project config Pages Viewer
CPEs cpe:2.3:a:config_pages_viewer_project:config_pages_viewer:*:*:*:*:*:drupal:*:*
Vendors & Products Config Pages Viewer Project
Config Pages Viewer Project config Pages Viewer

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00034}

epss

{'score': 0.0004}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00022}

epss

{'score': 0.00034}


Thu, 10 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
Description Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.
Title Config Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086
Weaknesses CWE-306
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2025-07-10T14:15:57.161Z

Reserved: 2025-07-02T16:07:06.702Z

Link: CVE-2025-7031

cve-icon Vulnrichment

Updated: 2025-07-10T14:15:38.863Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-08T21:15:28.907

Modified: 2025-09-04T17:07:53.290

Link: CVE-2025-7031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T22:31:26Z