PT-2025-47345 · Drupal · Drupal
Anna Kalata
+10
·
Published
2025-11-18
·
Updated
2025-11-25
·
CVE-2025-13081
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions 8.0.0 through 10.4.9
Drupal versions 10.5.0 through 10.5.6
Drupal versions 11.0.0 through 11.1.9
Drupal versions 11.2.0 through 11.2.7
Description
Drupal core contains an improperly controlled modification of dynamically-determined object attributes, leading to Object Injection. This allows for potential manipulation of objects within the system.
Recommendations
Update Drupal core to version 10.4.9 or later.
Update Drupal core to version 10.5.6 or later.
Update Drupal core to version 11.1.9 or later.
Update Drupal core to version 11.2.8 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal