Impact
A missing authorization check in the Drupal Data field module lets attackers forcefully browse URLs and retrieve sensitive data. The flaw is an example of inadequate access control, allowing any user to view content they should not be able to. The resulting exposure can compromise confidentiality of information stored in data fields.
Affected Systems
The vulnerability affects the Drupal Data field module in the Drupal platform. Versions from 0.0.0 up to and including 2.0.13 are affected. Administrators should verify the module version they run and consider upgrading to a fixed release.
Risk and Exploitability
Because no EPSS score is available, the likelihood of exploitation is not quantified, and the issue is not listed in the CISA KEV catalog, it is considered a lower‑profile risk. However, as the flaw permits forced browsing of arbitrary data field pages, it is exploitable via a web request from any authenticated or unauthenticated user, assuming the target site exposes the module’s endpoints. The absence of a CVSS assignment in the data makes it unclear how severe the impact is scored. It remains a significant concern for sites that expose sensitive data through the Data field module.
OpenCVE Enrichment