Missing Authorization in Drupal Facets Allows Forceful Browsing
CVE-2025-9549
6.5MEDIUM
What is CVE-2025-9549?
A missing authorization vulnerability exists in the Drupal Facets module, which can lead to forceful browsing. This vulnerability primarily affects versions prior to 2.0.10 and 3.0.1, allowing unauthorized users to access restricted content. Malicious actors could exploit this flaw to manipulate user sessions and gain access to sensitive information, posing a significant threat to data security.
Affected Version(s)
Facets 0.0.0 < 2.0.10
Facets 3.0.0 < 3.0.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Damien McKenna (damienmckenna)
Benji Fisher (benjifisher)
Joris Vercammen (borisson_)
Damien McKenna (damienmckenna)
Thomas Seidl (drunken monkey)
Jimmy Henderickx (strykaizer)
Benji Fisher (benjifisher)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Cathy Theys (yesct)
