Impact
Drupal FlowDrop suffers from a Missing Authorization flaw, allowing attackers to forcefully browse URLs and retrieve content that should be protected. This weakness could expose confidential data or allow modification of content without proper permissions, undermining the integrity of the site and potentially granting control over site functions. The severity is moderate, as the exploit requires no special privileges other than the ability to send HTTP requests, but it can significantly broaden an attacker’s view of the system. This Missing Authorization flaw862.
Affected Systems
All installations of the Drupal FlowDrop component from version 0.0.0 up to and including 1.6.0 are vulnerable. This includes any web sites that have deployed these versions without later updates.
Risk and Exploitability
The vulnerability is exploitable via standard web requests; an attacker may craft URLs to access restricted pages or resources. Because the EPSS score is less than 1% and the issue is not listed in CISA KEV, there is no publicly known exploit code, but the underlying missing authorization plainly permits unauthorized browsing. The risk remains moderate to high given the potential for significant data exposure or unauthorized configuration changes.
OpenCVE Enrichment