[CIVN-2025-0170] Multiple Vulnerabilities in Drupal Modules

By Published On: August 11, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Drupal Modules 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Drupal Config Pages versions prior to 2.18.0
Drupal Google Tag Manager (GTM) versions prior to 1.10.0
Overview
Multiple vulnerabilities have been reported in Drupal modules, which could be exploited by an attacker to bypass security restrictions and perform cross site scripting attack on the targeted system.
Target Audience:
Individuals and end-user organizations using Drupal Modules.
Risk Assessment:
High risk of unauthorized access and system instability.
Impact Assessment:
Potential for data theft and system compromise.
Description
Drupal is an open-source content management system (CMS) which allows individuals and organizations to create, manage and
maintain websites and web applications.
These vulnerabilities exist in the Drupal modules due to improper access control and insufficient input sanitization of user supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to bypass security restrictions and perform cross site scripting attack on the targeted system.
Solution
Apply appropriate updates as mentioned:
https://www.drupal.org/project/config_pages/releases/8.x-2.18
https://www.drupal.org/project/gtm/releases/8.x-1.10
Vendor Information
Drupal
https://www.drupal.org/sa-contrib-2025-093
https://www.drupal.org/sa-contrib-2025-094
References
Drupal
https://www.drupal.org/sa-contrib-2025-093
https://www.drupal.org/sa-contrib-2025-094
CVE Name
CVE-2025-28361
CVE-2025-28362
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmiaAY4ACgkQ3jCgcSdc
ys+ESQ//SEZMTSE4Ae3os4lrRgZSfaPqbBCXP9bMZNMijlTjkAfEKkyciimIasnt
APp5TXZPD9tOiJSL6cxERjKVZjhRX1ZcA+AidW9LGUc+M/VTu9qYE1eLMN1d1mfo
ExyRx0U3XE3rl7UtCc4K2FHbFkwqsgJuuKYvfA4dx7pyXR7fvc+u9xu8ZPWHnHbT
npgz/P4No3UCVlcDG9BWpnHt0KYSLELCfeVP3gb+zMuUPekdL+m4tnyPea1u7p28
P5PdSX6sdwwLboxpaPd46PFaDM923ba8JOlOU758pGDIcTAgbN4gdlMwYrJ90LdM
Qo/vA3C115wyzHbful5WjIc8zt55Uf1sQmJPV9pvSFnHmh0SvL4UKhm2ySMYLyww
Y/572bs6yuOqS2PDHVIsyzMsTLG84e0DeHsP2J6dYzmhb3OmC/setj9m7UJ58QEi
Z3v5BqtSionmgx3aUBbWFfbshZ7zANnm8q7X3LhHn5V0SG8+WYlEqjbZAKJTPBDF
pcu3zF5ey1PWyrX2F3SOwmcwY7NEMly5oHYZTzuwfEaQoaxMIma4dB/rcKftJ2UZ
CixgH1kPvwAbs6zLLPc0PMn+ChbD3tPtP6HKC+xCh1zhqGmD/UX9U3zBcuwIHPOX
oMKOBISZDpKRMWthvUpHjGGfDLqDfcFnJhnADjkCKGnsUOT5BV8=
=VvZW
—–END PGP SIGNATURE—–

Share this article