4.3
CVSSv2

CVE-2020-13674

Published: 11/02/2022 Updated: 18/02/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal

Vendor Advisories

The Drupal QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed Removing the "access in-place editing" permission from untru ...