Impact
The vulnerability is a missing authorization check in Drupal LocalGov Workflows. This check allows forceful browsing, enabling an attacker to view data or resources that should be protected. The result can be the disclosure of sensitive information, compromising confidentiality. The flaw is categorized as CWE-862, representing missing or insufficient authorization.
Affected Systems
Drupal LocalGov Workflows is the affected product, with versions ranging from 0.0.0 to 1.6.0 listed as impacted. No other vendors or products are referenced by the CNA.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw manifests as unauthorized browsing, so the most likely attack vector is a remote web interface, enabling both authenticated and unauthenticated users to forcefully access protected resources. The advisory labels the issue as moderately critical, and the flaw is not listed in CISA KEV. An attacker who can exploit this missing authorization may retrieve confidential data or use the information to further compromise the system.
OpenCVE Enrichment