Drupal Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2020-13674 - Vulnerability Database

Drupal Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2020-13674

Medium
Reference: CVE-2020-13674
Title: Drupal Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

The QuickEdit module does not properly validate access to routes which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the quotaccess in-place editingquot permission from untrusted users will not fully mitigate the vulnerability.