PT-2026-76591 · Drupal+2 · Quick Tabs+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Quick Tabs versions 0.0.0 through 4.3.1
Description
An incorrect authorization issue allows forceful browsing. The module fails to correctly enforce access when rendering node and block tabs by treating neutral access results as grants for node tabs and block plugins. Additionally, no access check is performed for reusable custom blocks. This allows users without proper permissions to view restricted content, such as unpublished nodes or unpublished reusable custom blocks. The risk is limited because the content exposed is pre-selected by a user with the
administer quicktabs permission during configuration.Recommendations
Update Drupal Quick Tabs to a version later than 4.3.1.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick Tabs
Drupal/Quicktabs