-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability arises because Drupal's Form API in 6.x did not check '#access' flags on submit buttons during submission handling. The functions responsible for processing form input (_form_button_was_clicked) and overall form execution (drupal_process_form) would have been the logical points where access control was omitted. These functions are in includes/form.inc, as this is where form submission logic is centralized in Drupal 6. The lack of '#access' validation in these critical paths allowed attackers to trigger restricted actions by forging submissions to hidden buttons.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/core | composer | >= 6.0, < 6.38 | 6.38 |
| drupal/drupal | composer | >= 6.0, < 6.38 | 6.38 |
Ongoing coverage of React2Shell