CVE-2025-8361
This module enables you to access an edit page for a config page.
The module doesn't sufficiently check the access permissions (hookENTITYTYPE_access() wasn't taken into account).
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit ID config page" and that it only affects sites that have access restricted via the hookENTITYTYPE_access() hook.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://www.drupal.org/sa-contrib-2025-093
