PT-2019-20532 · Packagist · Drupal/Existing Values Autocomplete Widget

Published

2019-07-24

·

Updated

2019-07-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module provides an autocomplete widget for text fields that suggests all existing (previously entered) values for that field.
The module doesn't sufficiently check for proper access permission before returning autocomplete results.
This vulnerability is mitigated by the fact that an attacker must know the route to the autocomplete callback controller though this is easily known.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2019-060

Affected Products

Drupal/Existing Values Autocomplete Widget