VDB
CVE-2020-13674
CVE-2020-13674
PUBLISHED
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.
EPSS 0.14% · 33.9th percentile
Risk Scores
EPSS Score
0.14%
33.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | drupal | 8.9.0, 9.2.0, 9.1.0 |
| Bitnami | drupal | 8.9.0, 9.1.0, 9.2.0 |
Exploit Intelligence
Timeline
- Sep 15, 2021 CVE Published
- Feb 12, 2022 EPSS Score
- Apr 5, 2022 EPSS Score
- May 28, 2022 EPSS Score
- Jul 20, 2022 EPSS Score
- Sep 10, 2022 EPSS Score
- Nov 2, 2022 EPSS Score
- Dec 24, 2022 EPSS Score
- Feb 14, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 7, 2023 EPSS Score
- May 30, 2023 EPSS Score