QID 154138
Date Published: 2023-05-24
QID 154138: Drupal Core: Access Bypass Vulnerability (CVE-2022-25274)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content.
This vulnerability only affects sites using Drupal's revision system.
Affected Versions:
Drupal from 9.3.0 to 9.3.11
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
This vulnerability allows users who have general access to revisions of content, but not to individual items of node and media content, to bypass access restrictions.
For more information visit Drupal security advisory SA-CORE-2022-009.
- SA-CORE-2022-009 -
www.drupal.org/sa-core-2022-009
CVEs related to QID 154138
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-009 |
|