← back
CVE-2022-25274

CVE-2022-25274

CVSS 5.4 MEDIUMEPSS 0.4%CWE-863
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Apr 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
Drupal · Core

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →