« Volver al listado

CVE-2025-13980

Estado: AnalizadaMedia (5.3)—

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-13980",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-13980",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-29T17:11:20.684032Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "mlhess@drupal.org",
      "affectedData": [
        {
          "repo": "https://git.drupalcode.org/project/ckeditor5_premium_features",
          "vendor": "Drupal",
          "product": "CKEditor 5 Premium Features",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "1.2.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.3.0",
              "lessThan": "1.3.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.4.0",
              "lessThan": "1.4.3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.5.0",
              "lessThan": "1.5.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.6.0",
              "lessThan": "1.6.4",
              "versionType": "semver"
            }
          ],
          "collectionURL": "https://www.drupal.org/project/ckeditor5_premium_features",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-28T20:16:07.260",
  "references": [
    {
      "url": "https://www.drupal.org/sa-contrib-2025-118",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mlhess@drupal.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mlhess@drupal.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-288"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en Drupal CKEditor 5 Premium Features permite la omisión de funcionalidad. Este problema afecta a CKEditor 5 Premium Features: desde 0.0.0 anterior a 1.2.10, desde 1.3.0 anterior a 1.3.6, desde 1.4.0 anterior a 1.4.3, desde 1.5.0 anterior a 1.5.1, desde 1.6.0 anterior a 1.6.4."
    }
  ],
  "lastModified": "2026-06-17T08:35:06.577",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cksource:ckeditor_5_premium_features:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E356BC4A-75C9-4C90-A3FA-DAEEF2556256",
              "versionEndExcluding": "1.2.10"
            },
            {
              "criteria": "cpe:2.3:a:cksource:ckeditor_5_premium_features:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "970E13D7-B17E-4555-9323-BBD8ED2ACE32",
              "versionEndExcluding": "1.3.6",
              "versionStartIncluding": "1.3.0"
            },
            {
              "criteria": "cpe:2.3:a:cksource:ckeditor_5_premium_features:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E780389-2123-4DE1-BC73-65058058E512",
              "versionEndExcluding": "1.4.3",
              "versionStartIncluding": "1.4.0"
            },
            {
              "criteria": "cpe:2.3:a:cksource:ckeditor_5_premium_features:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B917611A-AABA-42E1-BFEE-8806C45F0DAC",
              "versionEndExcluding": "1.6.4",
              "versionStartIncluding": "1.6.0"
            },
            {
              "criteria": "cpe:2.3:a:cksource:ckeditor_5_premium_features:1.5.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C821D675-E992-4D43-82EA-1A2E4DA3B412"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mlhess@drupal.org"
}