—
DRUPAL-CONTRIB-2025-093
Details
This module enables you to access an edit page for a config page.
The module doesn't sufficiently check the access permissions (`hook_ENTITY_TYPE_access()` wasn't taken into account).
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit ID config page" and that it only affects sites that have access restricted via the `hook_ENTITY_TYPE_access()` hook.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/config_pages
Introduced in:
0Fixed in: 2.18.0Upgrade drupal/config_pages to 2.18.0 or newer (ecosystem packagist:https://packages.drupal.org/8).