7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.
Basic Information
ID
CVE-2025-14840
Source
drupal
Published
Jan 28, 2026 at 20:03
Modified
Jan 29, 2026 at 16:30
Affected Product
Vendor
Drupal
Product
HTTP Client Manager
Version
0.0.0
Affected Versions
Drupal HTTP Client Manager 0.0.0
Drupal HTTP Client Manager 10.0.0
Drupal HTTP Client Manager 11.0.0
Drupal HTTP Client Manager 10.0.0
Drupal HTTP Client Manager 11.0.0