Project:
Date:
2025-July-02
Vulnerability:
Access bypass
Affected versions:
<1.0.4
CVE IDs:
CVE-2025-7031
Description:
This module enables you to use config_pages as a content entity.
The module doesn't check permission or entity access before rendering config_pages content.
Solution:
Install the latest version:
- If you use the Config Pages Viewer module at version 1.0.3 and lesser, upgrade to Config Pages Viewer 1.0.4.
Reported By:
Fixed By:
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team