CVE-2020-13674

CVE-2020-13674

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.

Source: CVE-2020-13674

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다