Логотип exploitDog
bind:CVE-2020-13674
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-13674

Количество 2

Количество 2

nvd логотип

CVE-2020-13674

больше 3 лет назад

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j586-cj67-vg4p

больше 3 лет назад

Cross-Site Request Forgery in Drupal core

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-13674

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-j586-cj67-vg4p

Cross-Site Request Forgery in Drupal core

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу