Impact
The vulnerability is a missing authorization check in the Drupal Paragraphs module, which allows attackers to forcefully browse paragraph content. This flaw is classified as CWE-862, representing an access control weakness that can expose sensitive data and potentially enable unauthorized editing of paragraph entities. The impact is the compromise of confidentiality and integrity of paragraph information, allowing unauthorized users to read or modify content without legitimate authentication.
Affected Systems
Drupal Paragraphs, version range 0.0.0 through 1.21.0, are affected. All installations within this range may allow unauthenticated access to paragraph data and endpoints.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in CISA KEV, indicating that the probability of exploitation is currently very low. The flaw can be exploited remotely by sending HTTP requests to paragraph endpoints that lack proper access controls. No authentication is required, so the attack vector is likely wide open to any network user. The CVSS score is 6.5, signifying medium severity, and the overall risk remains moderate, but the absence of a patch makes it a high priority for remediation.
OpenCVE Enrichment