First published: Wed Jul 20 2022(Updated: )
Drupal core - Moderately critical - Access Bypass - SA-CORE-2022-013
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0.0<9.3.19>=9.4.0<9.4.3 | |
Drupal Drupal | >=8.0.0<9.3.19 | |
Drupal Drupal | >=9.4.0<9.4.3 | |
composer/drupal/core | >=9.4.0<9.4.3 | 9.4.3 |
composer/drupal/core | >=8.0.0<9.3.19 | 9.3.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25278 is a vulnerability in Drupal core that allows a user to alter data they should not have access to.
The severity of CVE-2022-25278 is classified as moderately critical.
Drupal core versions 8.0.0 to 9.3.19 and 9.4.0 to 9.4.3 are affected by CVE-2022-25278.
No, forms provided by Drupal core are not known to be vulnerable to CVE-2022-25278.
You can find more information about CVE-2022-25278 on the Drupal website at https://www.drupal.org/sa-core-2022-013.