CVE-2025-13985
BaseFortify
Publication date: 2026-01-28
Last updated on: 2026-02-06
Assigner: Drupal.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ithom | entity_share | to 3.13.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Incorrect Authorization issue in the Drupal Entity Share module that allows Forceful Browsing. It affects versions from 0.0.0 before 3.13.0, meaning unauthorized users may be able to access resources or entities they should not have permission to view by bypassing normal access controls.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing unauthorized access to sensitive or restricted data within the Drupal Entity Share module. Attackers could browse and access entities without proper authorization, potentially leading to data exposure or misuse.