Impact
The vulnerability is an improperly controlled modification of dynamically‑determined object attributes that permits object injection in the Drupal authorization, as defined by CWE‑915.
Affected Systems
The affected versions are Drupal ECA: Event – Condition – Action 0.0.0 through 2.1.20, 3.0.0 through 3.0.12, and 3.1.0 through 3.1.4. Any site running these releases is at risk.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity, and the EPSS score of <1% indicates a very low but non‑zero probability of exploitation. It is not listed in CISA KEV. The likely attack vector is remote, deriving from user input or module configuration files, with no obvious local privilege prerequisites.
OpenCVE Enrichment