CVE-2022-25270Incorrect Authorization in Drupal Core

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 51.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateFeb 18

Description

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5drupal/core9.3.x9.3.6+1
Packagistdrupal/core9.3.09.3.6+1
NVDdrupal/drupal9.2.09.2.13+1

Patches

🔴Vulnerability Details

4
OSV
Incorrect authorization in Drupal core2022-02-18
GHSA
Incorrect authorization in Drupal core2022-02-18
CVEList
CVE-2022-25270: The Quick Edit module does not properly check entity access in some circumstances2022-02-16
OSV
CVE-2022-25270: The Quick Edit module does not properly check entity access in some circumstances2022-02-16

📋Vendor Advisories

1
Drupal
Drupal core - Moderately critical - Information disclosure - SA-CORE-2022-0042022-02-16
CVE-2022-25270 — Incorrect Authorization in Drupal Core | cvebase