—
DRUPAL-CONTRIB-2019-060
Details
This module provides an autocomplete widget for text fields that suggests all existing (previously entered) values for that field.
The module doesn't sufficiently check for proper access permission before returning autocomplete results.
This vulnerability is mitigated by the fact that an attacker must know the route to the autocomplete callback controller though this is easily known.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/existing_values_autocomplete_widget
Introduced in:
0Fixed in: 1.2.0Upgrade drupal/existing_values_autocomplete_widget to 1.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).