Drupal Node Export Deserialization Vulnerability Allowing Object Injection

Vulnerability

A deserialization vulnerability allowing object injection has been identified in the Node export module for Drupal. This issue affects versions 7.X-* prior to 7.X-3.3.

Impact

Exploitation of this vulnerability could lead to object injection, which may be used to manipulate application logic or execute arbitrary code, depending on the injected object's class and the application's handling of it.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.