Impact
This vulnerability is a missing authorization flaw that permits forceful browsing, allowing attackers to access restricted content and configuration settings that should be protected. It is identified by CWE‑862, underlining the absence of proper access control enforcement. An attacker who can discover URLs or resources may retrieve sensitive information or execute privileged actions without proper authentication, potentially exposing confidential data.
Affected Systems
The flaw affects the Drupal \"Examples for Developers\" module in all releases from 0.0.0 through 4.0.6. Users deploying any of these versions may be exposed to unauthorized access to module content and management functionality.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability has not been listed in the CISA KEV catalog, indicating that no large‑scale exploits are currently documented. The attack vector is most likely a standard HTTP request to non‑existent or protected pages (forceful browsing). The CVSS score of 3.3 indicates low severity, but the lack of authentication in the affected module means any user with network access to the Drupal instance could potentially exploit the flaw if the module is installed and accessible.
OpenCVE Enrichment