Impact
The Lunr exposed filters component in Drupal allows attackers to provide arbitrary filter values that bypass the intended restrictions. This flaw arises from improper input validation (CWE‑20) and inadequate access control (CWE‑284), enabling the retrieval of content that should otherwise be hidden from the requesting user. The result is the disclosure of sensitive or confidential information to unauthorized parties.
Affected Systems
All Drupal installations that include the Lunr exposed filters component are impacted. No specific version information is provided; therefore, any version using this component should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score for this vulnerability is 5.7, indicating a moderate likelihood of serious impact if successfully exploited. The EPSS score is less than 1%, implying a low probability of exploitation in the current landscape. Exploitation would likely occur via crafted HTTP requests that manipulate the exposed filter parameters, a remote attack. The vulnerability is not listed in CISA's KEV catalog, so no known active exploitation is documented.
OpenCVE Enrichment