Access Control Issue in Drupal's QuickEdit Module
CVE-2020-13676

6.5MEDIUM

Key Information:

Vendor
Drupal
Status
Vendor
CVE Published:
11 February 2022

Summary

The QuickEdit module in Drupal fails to adequately verify user permissions for specific fields under certain conditions, which could result in unauthorized access to sensitive field data. This issue arises only when the QuickEdit module, part of the Standard profile, is active on a site.

Affected Version(s)

Core 9.2 < 9.2.6

Core 9.1 < 9.1.13

Core 8.9 < 8.9.19

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.