Drupal Simple OAuth (OAuth2) & OpenID Connect是Drupal社区的一款授权框架。 Drupal Simple OAuth (OAuth2) & OpenID Connect 6.0.0版本至6.0.7之前版本存在安全漏洞,该漏洞源于认证绕过漏洞,可能导致认证绕过。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Simple OAuth (OAuth2) & OpenID Connect | 6.0.0 ~ 6.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12083 | CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-11 | |
| CVE-2025-12082 | CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025- | |
| CVE-2025-10929 | Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111 | |
| CVE-2025-10930 | Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-110 | |
| CVE-2025-10931 | Umami Analytics - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-109 | |
| CVE-2025-10928 | Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108 | |
| CVE-2025-10927 | Plausible tracking - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-107 | |
| CVE-2025-10926 | JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106 | |
| CVE-2025-9954 | Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025 |
No comments yet