Loading HuntDB...

GHSA-j586-cj67-vg4p

GitHub Security Advisory

Cross-Site Request Forgery in Drupal core

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.

Affected Packages

Packagist drupal/core
Affected versions: 8.0.0 (fixed in 8.9.19)
Packagist drupal/core
Affected versions: 9.1.0 (fixed in 9.1.13)
Packagist drupal/core
Affected versions: 9.2.0 (fixed in 9.2.6)

Related CVEs

Key Information

GHSA ID
GHSA-j586-cj67-vg4p
Published
February 12, 2022 12:00 AM
Last Modified
February 23, 2022 7:23 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
drupal/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.