PT-2026-69022 · Drupal+2 · Edit In-Place Field+1
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Edit in-place field versions 0.0.0 through 2.1.1
Description
An incorrect authorization issue allows forceful browsing when editing entities. The module fails to sufficiently verify access rights, enabling a malicious user to craft requests to modify any field on any entity. This issue is mitigated if the attacker lacks the "edit in place field editing permission" role.
Recommendations
Update Edit in-place field to a version later than 2.1.1.
Exploit
Fix
Improper Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Edit In-Place Field
Drupal/Edit In Place Field