CVE-2025-31674

CVE-2025-31674: Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003

Vendor Drupal
Product Drupal core
Weakness CWE-915
Published March 31, 2025
Last update April 3, 2025

CVSS base score

What the vulnerability does

01Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

Key dates

02Disclosure timeline

March 31, 2025 CVE published
April 3, 2025 Record updated

Related vulnerabilities

04Related CVE