[WID-SEC-2025-1451] Drupal: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen CVSS Base Score 8.2 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff ja Datum 02.07.2025 Stand UPDATE 29.05.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 02.07.2025 Open Source Drupal Config Pages Viewer <1.0.4 Open Source Drupal Two-factor Authentication (TFA) <1.11.0 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in Drupal, including in the Config Pages Viewer (<1.0.4) and Two-factor Authentication (TFA) (<1.11.0) modules, allow attackers to bypass security measures. The CVSS base score for this remote attack vector is 8.2 (High). Administrators should upgrade affected modules to at least Config Pages Viewer 1.0.4 and TFA 1.11.0 to mitigate the risk.