VDB
CVE-2020-13674
CVE-2020-13674
PUBLISHED
CVSS 6.5 MEDIUM
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.
EPSS 0.46% · 38.0th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.46%
38.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | drupal | 8.9.0, 9.2.0, 9.1.0 |
| Bitnami | drupal | 8.9.0, 9.1.0, 9.2.0 |
Timeline
- Sep 15, 2021 CVE Published
- Feb 12, 2022 EPSS Score
- Apr 5, 2022 EPSS Score
- May 28, 2022 EPSS Score
- Jul 20, 2022 EPSS Score
- Sep 11, 2022 EPSS Score
- Nov 2, 2022 EPSS Score
- Dec 25, 2022 EPSS Score
- Feb 15, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 9, 2023 EPSS Score
- May 31, 2023 EPSS Score