CyberRota Analysis
AI-GeneratedDrupal ECA: Event - Condition - Action versions 0.0.0 to 2.1.20, 3.0.0 to 3.0.12, and 3.1.0 to 3.1.4 are vulnerable to an object injection attack due to improperly controlled modification of dynamically-determined object attributes. This vulnerability could allow an attacker to manipulate object attributes, potentially leading to unauthorized access or actions within the application. Organizations using these specific versions of Drupal ECA should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.