CVE-2022-25270
17.02.2022, 00:15
The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.Enginsight
Vendor | Product | Version |
---|---|---|
drupal | drupal | 9.2.0 ≤ 𝑥 < 9.2.13 |
drupal | drupal | 9.3.0 ≤ 𝑥 < 9.3.6 |
𝑥
= Vulnerable software versions