PT-2025-47344 · Drupal · Drupal

Alex Pott

+15

·

Published

2025-11-18

·

Updated

2025-11-25

·

CVE-2025-13080

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Drupal versions 8.0.0 through 10.4.9 Drupal versions 10.5.0 through 10.5.6 Drupal versions 11.0.0 through 11.1.9 Drupal versions 11.2.0 through 11.2.8
Description An improper check for unusual or exceptional conditions exists in Drupal core, allowing for forceful browsing. This issue impacts the software's ability to handle unexpected input or situations, potentially leading to unauthorized access or information disclosure.
Recommendations Update Drupal core to version 10.4.9 or later. Update Drupal core to version 10.5.6 or later. Update Drupal core to version 11.1.9 or later. Update Drupal core to version 11.2.8 or later.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DRUPAL-2025-13080
CVE-2025-13080
DRUPAL-CORE-2025-005
GHSA-83V7-C2CF-P9C2

Affected Products

Drupal