Impact
Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal core introduces a PHP object injection flaw. The vulnerability allows an attacker to craft input that manipulates internal object attributes, leading to the creation or alteration of PHP objects at runtime. This can result in arbitrary execution of code or other malicious behaviors on the web server, compromising confidentiality and integrity. The weakness corresponds to CWE-915.
Affected Systems
Drupal core versions from 0.0.0 through 10.5.12, 10.6.0 through 10.6.11, 11.2.0 through 11.2.14, 11.3.0 through 11.3.12, as well as all sub‑version releases through 11.0.x and 11.1.x are affected; in short, any installation of Drupal core up to and including 11.3.12 is vulnerable.
Risk and Exploitability
The CVSS base score of 5.9 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The lack of explicit attack vector information implies the exploit most likely requires remote or authenticated input that allows manipulation of object attributes, possibly via dynamically generated forms or API endpoints. Thus, the risk is moderate but warrants timely remediation.
OpenCVE Enrichment