logo

Database

Improper authorization control for web services In drupal/editoria11y

Description

This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.

The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-VAUES – Vulnerability | Fluid Attacks Database