Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
2025-11-18T17:15:58.987
2025-11-24T17:43:15.717
Analyzed
CVSSv3.1: 5.9 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | drupal | drupal | < 10.4.9 | Yes |
| Application | drupal | drupal | < 10.5.6 | Yes |
| Application | drupal | drupal | < 11.1.9 | Yes |
| Application | drupal | drupal | < 11.2.8 | Yes |