Authorization Bypass in Drupal Open Social Affects Vulnerable Versions
CVE-2025-31685

9.1CRITICAL

Key Information:

Vendor
Drupal
Vendor
CVE Published:
31 March 2025

Summary

A critical vulnerability in Drupal Open Social has been identified, allowing unauthorized users to access restricted resources through forceful browsing techniques. This issue affects specific versions of Open Social, rendering them susceptible to exploitation and potentially compromising sensitive data. It's essential for users of affected versions to implement security measures and update to secure releases.

Affected Version(s)

Open Social 0.0.0 < 12.3.11

Open Social 12.4.0 < 12.4.10

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert Ragas (robertragas)
zanvidmar
Denis Kolmerschlag (uber_denis)
zanvidmar
Greg Knaddison (greggles)
.