Access Validation Bypass in QuickEdit Module for Drupal
CVE-2020-13674

6.5MEDIUM

Key Information:

Vendor
Drupal
Status
Vendor
CVE Published:
11 February 2022

Summary

The QuickEdit module for Drupal fails to properly validate user access to key routes, potentially exposing sites to cross-site request forgery (CSRF) attacks. This vulnerability can compromise data integrity and security within installations that include the QuickEdit module as part of the Standard profile. Simply removing the 'access in-place editing' permission from untrusted users is not a sufficient safeguard against exploitation, highlighting the need for comprehensive access control measures.

Affected Version(s)

Core 9.2 < 9.2.6

Core 9.1 < 9.1.13

Core 8.9 < 8.9.19

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.