Impact
The Drupal Clean RESTful module contains a vulnerability that is described as allowing unspecified behavior, but the exact operation is not detailed in the provided description. The vulnerability is classified under CWE‑287, indicating an authentication or authorization weakness. The impact could involve unauthorized access to resources exposed by the module, potentially allowing attackers to read, modify, or delete data. Specific attacker capabilities are not detailed in the original description.
Affected Systems
Drupal Clean RESTful module versions *.* are affected. Any Drupal website that has this module enabled, regardless of the Drupal core version, remains vulnerable until the module is patched or removed.
Risk and Exploitability
An EPSS score of <1% indicates a low current exploitation probability, while a CVSS score of 5.9 places the issue in the moderate range and it is not listed in the CISA KEV catalog. The likely attack vector is over HTTP or HTTPS by sending crafted requests to the module’s REST endpoints. Attackers would attempt to exploit the authentication or authorization weakness to gain unauthorized access to protected resources.
OpenCVE Enrichment