Impact
Missing Authorization in Drupal FlowDrop enables forceful browsing of pages that should be protected by authentication or authorization attacker with web access to the FlowDrop instance to request URLs that are normally restricted, potentially exposing sensitive data or user information. The CVSS score of 5.4 signifies a moderate severity, indicating that the missing authorization check represents a significant compromise of confidentiality and integrity.
Affected Systems
Drupal FlowDrop versions from 0.0.0 through 1.6.0 are affected. Any installation within this range without additional access controls would be vulnerable.
Risk and Exploitability
Attackers would need to send HTTP requests to restricted routes that normally require authentication or authorization. The EPSS score indicates less than a 1% probability of exploitation at this time. Because the vulnerability permits unauthorized access to protected resources, exploitation could lead to privacy and integrity risks. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploitation of this issue.
OpenCVE Enrichment