Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.
| Vendor | Product | Versions |
|---|---|---|
| drupal | eca: event - condition - action | 0.0.0, 3.0.0, 3.1.0 |
Updated severity to CRITICAL, added affected versions up to 2.1.19/3.0.11/3.1.3, and noted that there is no available exploit.
Initial creation