Loading HuntDB...

GHSA-73q4-j324-2qcc

GitHub Security Advisory

Incorrect authorization in Drupal core

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

Affected Packages

Packagist drupal/core
Affected versions: 9.3.0 (fixed in 9.3.6)
Packagist drupal/core
Affected versions: 8.0.0 (fixed in 9.2.13)

Related CVEs

Key Information

GHSA ID
GHSA-73q4-j324-2qcc
Published
February 18, 2022 12:00 AM
Last Modified
March 1, 2022 10:04 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
drupal/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.