First published: Fri Feb 11 2022(Updated: )
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0.0<8.9.19 | 8.9.19 |
composer/drupal/core | >=9.2.0<9.2.6 | 9.2.6 |
composer/drupal/core | >=9.1.0<9.1.13 | 9.1.13 |
Drupal Drupal | >=8.9.0<8.9.19 | |
Drupal Drupal | >=9.1.0<9.1.13 | |
Drupal Drupal | >=9.2.0<9.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13676 is a vulnerability in the QuickEdit module for Drupal that can lead to unintended disclosure of field data.
CVE-2020-13676 affects Drupal sites if the QuickEdit module is installed, potentially exposing field data.
Versions 8.0.0 to 8.9.19 and versions 9.1.0 to 9.1.13 of Drupal are affected by CVE-2020-13676.
Yes, there is a remedy available for CVE-2020-13676. Apply Drupal core version 8.9.19, 9.2.6, or 9.1.13 to fix the vulnerability.
CVE-2020-13676 has a severity score of 6.5, which is considered medium.