Vulnerability Description
The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | >= 9.2.0, < 9.2.13 |
Related Weaknesses (CWE)
References
- https://www.drupal.org/sa-core-2022-004PatchVendor Advisory
- https://www.drupal.org/sa-core-2022-004PatchVendor Advisory
FAQ
What is CVE-2022-25270?
CVE-2022-25270 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not author...
How severe is CVE-2022-25270?
CVE-2022-25270 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25270?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Drupal.