CVE-2020-13674
Cross-Site Request Forgery in Drupal core
6.5
MEDIUM
CVSS 3.1
EPSS 0.46%
Description
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.
How to fix CVE-2020-13674
To remediate CVE-2020-13674, upgrade the affected package to a fixed version below.
- —upgrade to 8.9.19 or later
- —upgrade to 8.9.19 or later
- —upgrade to 8.9.19 or later
Is CVE-2020-13674 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 8.9.0, < 8.9.19, >= 9.1.0, < 9.1.13, >= 9.2.0, < 9.2.6
- >= 8.0.0, < 8.9.19 | >= 9.1.0, < 9.1.13 | >= 9.2.0, < 9.2.6
- >= 8.0.0, < 8.9.19
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |