CVE Database
/

CVE-2022-25270

Back to search

CVE-2022-25270

Published: Feb 16, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

VendorProductVersions

Drupal

Core

affected
9.3.x - < 9.3.6
affected
9.2.x - < 9.2.13

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now