CVE-2025-7031

Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.
References
Link Resource
https://www.drupal.org/sa-contrib-2025-086 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:config_pages_viewer_project:config_pages_viewer:*:*:*:*:*:drupal:*:*

History

04 Sep 2025, 17:07

Type Values Removed Values Added
References () https://www.drupal.org/sa-contrib-2025-086 - () https://www.drupal.org/sa-contrib-2025-086 - Third Party Advisory
First Time Config Pages Viewer Project config Pages Viewer
Config Pages Viewer Project
CPE cpe:2.3:a:config_pages_viewer_project:config_pages_viewer:*:*:*:*:*:drupal:*:*

10 Jul 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

10 Jul 2025, 13:18

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de autenticación faltante para funciones críticas en Drupal Config Pages Viewer permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta al Visor de páginas de configuración: desde la versión 0.0.0 hasta la 1.0.4.

08 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 21:15

Updated : 2025-09-04 17:07


NVD link : CVE-2025-7031

Mitre link : CVE-2025-7031

CVE.ORG link : CVE-2025-7031


JSON object : View

Products Affected

config_pages_viewer_project

  • config_pages_viewer
CWE
CWE-306

Missing Authentication for Critical Function