PT-2019-20538 · Packagist · Drupal/Tablefield

Published

2019-09-18

·

Updated

2019-09-18

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module allows you to attach tabular data to an entity.
There is insufficient access checking for users with the ability to "Export Tablefield Data as CSV". They can export data from unpublished nodes or otherwise inaccessible entities.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Export Tablefield Data as CSV".
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2019-067

Affected Products

Drupal/Tablefield