Impact
Drupal core contains an Improperly Controlled Modification of Dynamically-Determined Object Attributes flaw (CWE‑915). When an attacker can influence data sent to Drupal, the system may create or modify object properties in unintended ways, allowing an attacker to inject arbitrary object attributes. The result can be unauthorized changes to application data or configuration, but the CVE description does not state or imply execution of arbitrary code.
Affected Systems
The flaw applies to every Drupal core installation whose version falls within the following ranges: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, and to every release in the 11.0.* and 11.1.* branches.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of current exploitation. The CVSS score of 5.9 reflects moderate severity, driven by the potential for data tampering. The attack vector is inferred to be a remote web request that supplies crafted data to the application; the presence of instructed object injection makes an attacker able to alter key application state if the vector is successfully exercised.
OpenCVE Enrichment