Intel

AIKIDO-2025-10475

drupal/single_content_sync is vulnerable to Missing Authorization

Missing AuthorizationCVE-2025-48009 Published Jul 17, 2025

53

Medium Risk

This Affects:

PHPdrupal/single_content_sync
1.0.0 - 1.4.11
Fixed in 1.4.12
Are you affected? Scan for Free

TL;DR

Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse. While the export feature rightfully bypasses implemented access controls, enabling it to extract all entity data, including private and confidential information, to the mentioned formats, it fails to adequately safeguard the generated output.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/single_content_sync is vulnerable to Missing Authorization in versions 1.0.0 - 1.4.11.

How to fix this

Upgrade the drupal/single_content_sync library to the patch version.