CVE-2025-13081
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-18

Last updated on: 2025-11-24

Assigner: Drupal.org

Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-18
Last Modified
2025-11-24
Generated
2026-05-07
AI Q&A
2025-11-18
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
drupal drupal From 8.0.0 (inc) to 10.4.9 (exc)
drupal drupal From 10.5.0 (inc) to 10.5.6 (exc)
drupal drupal From 11.0.0 (inc) to 11.1.9 (exc)
drupal drupal From 11.2.0 (inc) to 11.2.8 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal core, which allows Object Injection. It affects multiple versions of Drupal core before certain fixed versions. Essentially, it means that an attacker could manipulate object attributes dynamically in a way that was not properly controlled, potentially leading to malicious object injection.


How can this vulnerability impact me? :

The vulnerability can impact you by allowing an attacker with high privileges to inject malicious objects, which can lead to unauthorized modification of data or behavior within the Drupal application. According to the CVSS score, it has a high impact on confidentiality and integrity but does not affect availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart