CVE-2025-31674

CVE-2025-31674: Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003

Vendor Drupal
Product Drupal core
Weakness CWE-915
Published March 31, 2025
Last update April 3, 2025

CVSS base score

What the vulnerability does

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

Key dates

Disclosure timeline

March 31, 2025 CVE published
April 3, 2025 Record updated