VDB
EN

DRUPAL-CONTRIB-2026-093

상세

This module provides formatters to allow in-place editing in a View or other display (full content, teaser...).

The module doesn't sufficiently check access when editing entities. A malicious user could craft requests to allow them to modify any field on any entity.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit in place field editing permission".

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Packagist:https://packages.drupal.org/8 / drupal/edit_in_place_field
최초 영향 버전: 0 수정 버전: 2.1.1

Upgrade drupal/edit_in_place_field to 2.1.1 or newer (ecosystem packagist:https://packages.drupal.org/8).

참고