Missing Authorization Flaw in Drupal Config Pages
CVE-2025-8361
Currently unrated
What is CVE-2025-8361?
A missing authorization vulnerability has been identified in Drupal's Config Pages, which allows unauthorized users to perform forceful browsing. This issue affects all versions of Config Pages up to but not including 2.18.0, potentially compromising sensitive configuration settings.
Affected Version(s)
Config Pages 0.0.0 < 2.18.0