Server-Side Request Forgery Vulnerability in Drupal AI SEO Link Advisor
CVE-2025-8675

4.7MEDIUM

Key Information:

Vendor

Drupal

Vendor
CVE Published:
15 August 2025

What is CVE-2025-8675?

A Server-Side Request Forgery (SSRF) vulnerability in Drupal's AI SEO Link Advisor can be exploited by attackers to send crafted requests from the server, leading to unauthorized access to internal resources. The issue is present in versions of AI SEO Link Advisor prior to 1.0.6, potentially allowing malicious actors to gain sensitive information by manipulating server requests.

Affected Version(s)

AI SEO Link Advisor 0.0.0 < 1.0.6

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alberto Cocchiara (bigbabert)
Conrad Lara (cmlara)
Alberto Cocchiara (bigbabert)
Conrad Lara (cmlara)
Vishal Kadam (vishal.kadam)
Benji Fisher (benjifisher)
catch (catch)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
.
CVE-2025-8675 : Server-Side Request Forgery Vulnerability in Drupal AI SEO Link Advisor