What the vulnerability does
01Description
Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.
CVSS base score
What the vulnerability does
Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.
Explanation of Vulnerability in Simple Terms
The Entity Share module for Drupal contains an authorization flaw that allows users to access or modify shared content beyond their intended permissions. The vulnerability affects all versions before 3.13.0. Site administrators should update immediately to patch the authorization checks that govern entity sharing access.
What an attacker can do
Access or modify shared entities beyond their assigned permissions.
Potential impact on your site
Users may view or edit content they should not have access to, compromising content confidentiality and integrity.
Conditions required to exploit
User must have some level of access to the Entity Share module or shared content.
Key dates
External resources
Related vulnerabilities