QID 154104
Date Published: 2022-03-29
QID 154104: Drupal Core Information disclosure Vulnerability (SA-CORE-2022-004)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
In Drupal the Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access.
Affected Versions:
Drupal 9.3.0 to 9.3.6.
Drupal 9.2.0 to 9.2.13
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Note: Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
Successful exploitation of these vulnerabilities could affect Confidentiality.
Solution
Customers are advised to install latest drupal version.
For more information visit Drupal security advisory SA-CORE-2022-004.
For more information visit Drupal security advisory SA-CORE-2022-004.
Vendor References
- SA-CORE-2022-004 -
www.drupal.org/sa-core-2022-004
CVEs related to QID 154104
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| sa-core-2022-004 |
|