The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
References
| Link | Resource |
|---|---|
| https://www.drupal.org/sa-core-2022-004 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-16 16:15
Updated : 2022-02-25 06:34
NVD link : CVE-2022-25270
Mitre link : CVE-2022-25270
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
drupal
- drupal


