Access Validation Bypass in QuickEdit Module for Drupal
CVE-2020-13674
6.5MEDIUM
Summary
The QuickEdit module for Drupal fails to properly validate user access to key routes, potentially exposing sites to cross-site request forgery (CSRF) attacks. This vulnerability can compromise data integrity and security within installations that include the QuickEdit module as part of the Standard profile. Simply removing the 'access in-place editing' permission from untrusted users is not a sufficient safeguard against exploitation, highlighting the need for comprehensive access control measures.
Affected Version(s)
Core 9.2 < 9.2.6
Core 9.1 < 9.1.13
Core 8.9 < 8.9.19
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved