PT-2022-8501 · Quickedit · Quickedit

CVE-2020-13674

·

Published

2022-02-11

·

Updated

2024-03-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions QuickEdit module (affected versions not specified)
Description The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module is installed. Removing the access in-place editing permission from untrusted users will not fully mitigate the issue.
Recommendations For the QuickEdit module, consider removing or restricting the module until a proper fix is available. As a temporary workaround, restrict access to the QuickEdit module to trusted users only. Avoid granting the access in-place editing permission to untrusted users, as this does not fully mitigate the issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DRUPAL-2020-13674
CVE-2020-13674
DRUPAL-CORE-2021-007
GHSA-J586-CJ67-VG4P

Affected Products

Quickedit