QID 730456
Date Published: 2022-04-26
QID 730456: Drupal Core Access Bypass Vulnerability (SA-CORE-2022-009)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content.
Affected Versions:
Drupal versions from 9.3.x prior to Drupal 9.3.12
NOTE:
This vulnerability only affects sites using Drupal's revision system.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation of this vulnerability may allow an attacker to have access to unauthorized data.
For more information visitDrupal security advisory sa-core-2022-009
- SA-CORE-2022-009 -
www.drupal.org/sa-core-2022-009
CVEs related to QID 730456
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-009 |
|