PT-2026-46112 · Drupal+2 · Localgov Workflows+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LocalGov Workflows versions 0.0.0 through 1.6.0
Description
Missing authorization allows forceful browsing within the module, which configures default editorial workflows for content types, including content moderation, approvals dashboards, scheduling, and previews. The issue stems from insufficient access restrictions to a view of Service Contacts, which exposes the names and content items assigned to each Service Contact.
Recommendations
Update LocalGov Workflows to a version later than 1.6.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Localgov Workflows
Drupal/Localgov Workflows