First published: Fri Feb 11 2022(Updated: )
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | >=8.9.0<8.9.19 | |
Drupal Drupal | >=9.1.0<9.1.13 | |
Drupal Drupal | >=9.2.0<9.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13674 is a vulnerability in the QuickEdit module of Drupal that allows cross-site request forgery and potential data integrity issues.
Sites are only affected if the QuickEdit module is installed, which comes with the Standard profile of Drupal.
CVE-2020-13674 has a severity value of 6.5, which is considered medium.
To fix CVE-2020-13674, you should update Drupal to a version that includes the patch provided by Drupal. Refer to the official Drupal security advisory for detailed instructions.
You can find more information about CVE-2020-13674 and the recommended security measures in the official Drupal security advisory at https://www.drupal.org/sa-core-2021-007.