First published: Wed Feb 16 2022(Updated: )
The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | >=9.2.0<9.2.13 | |
Drupal Drupal | >=9.3.0<9.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Drupal vulnerability is CVE-2022-25270.
The title of this Drupal vulnerability is 'The Quick Edit module does not properly check entity access in some circumstances.'
The severity of CVE-2022-25270 is medium.
CVE-2022-25270 affects Drupal sites if they have the QuickEdit module installed and users with the 'access in-place editing' permission can view unauthorized content.
To fix CVE-2022-25270 in Drupal, update to versions 9.2.14 or 9.3.7 or apply the patch provided by Drupal.