Impact
The vulnerability is a missing Authorization flaw in the Drupal Entity PDF module that permits forceful browsing. Attackers can access PDF files that should be restricted, potentially exposing confidential or sensitive information. The weakness is identified as CWE-862, which indicates insufficient authorization checks.
Affected Systems
The flaw affects the Drupal CMS through its Entity PDF module. Any installation of Entity PDF version 0.0.0 up to and including 2.1.5 is vulnerable. Systems that host PDF documents via this module are at risk if they remain on these versions.
Risk and Exploitability
Because the risk involves unauthorized content disclosure, the impact could compromise data confidentiality. Although an EPSS score is not available and the vulnerability is not currently listed in CISA KEV, the lack of an authorization check implies a potential for exploitation if an attacker can create or guess valid URLs to PDF files. The vulnerability is likely exploitable over the web, as the module serves files via HTTP requests. The CVSS score of 5.4 indicates a moderate risk for exposed data.
OpenCVE Enrichment