Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18126 | Drupal Commerce Alphabank Redirect Incorrect Authorization vulnerability |
Github GHSA |
GHSA-48wx-8736-jgx2 | Drupal Commerce Alphabank Redirect Incorrect Authorization vulnerability |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-067 |
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 16 Jun 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commerce Alphabank Redirect Project
Commerce Alphabank Redirect Project commerce Alphabank Redirect |
|
| CPEs | cpe:2.3:a:commerce_alphabank_redirect_project:commerce_alphabank_redirect:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Commerce Alphabank Redirect Project
Commerce Alphabank Redirect Project commerce Alphabank Redirect |
Wed, 11 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 11 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3. | |
| Title | Commerce Alphabank Redirect - Moderately critical - Access bypass - SA-CONTRIB-2025-067 | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-06-11T15:48:21.281Z
Reserved: 2025-05-21T16:25:07.435Z
Link: CVE-2025-48446
Updated: 2025-06-11T15:48:09.655Z
Status : Analyzed
Published: 2025-06-11T15:15:42.427
Modified: 2025-06-16T16:38:19.400
Link: CVE-2025-48446
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA