Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alter data they should not have access to. No forms provided by Drupal core are known to be vulnerable. However, forms added through contributed or custom modules or themes may be affected.
References
History

Mon, 03 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published: 2023-04-26T00:00:00.000Z

Updated: 2025-02-03T18:40:32.316Z

Reserved: 2022-02-16T00:00:00.000Z

Link: CVE-2022-25278

cve-icon Vulnrichment

Updated: 2024-08-03T04:36:06.827Z

cve-icon NVD

Status : Modified

Published: 2023-04-26T15:15:08.747

Modified: 2025-02-03T19:15:09.573

Link: CVE-2022-25278

cve-icon Redhat

No data.