Missing Authorization in Drupal Facets Allows Forceful Browsing
CVE-2025-9549
Currently unrated
What is CVE-2025-9549?
A missing authorization vulnerability exists in the Drupal Facets module, which can lead to forceful browsing. This vulnerability primarily affects versions prior to 2.0.10 and 3.0.1, allowing unauthorized users to access restricted content. Malicious actors could exploit this flaw to manipulate user sessions and gain access to sensitive information, posing a significant threat to data security.
Affected Version(s)
Facets 0.0.0 < 2.0.10
Facets 3.0.0 < 3.0.1
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Damien McKenna (damienmckenna)
Benji Fisher (benjifisher)
Joris Vercammen (borisson_)
Damien McKenna (damienmckenna)
Thomas Seidl (drunken monkey)
Jimmy Henderickx (strykaizer)
Benji Fisher (benjifisher)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Cathy Theys (yesct)