Edit in-place field
An ordinary account on the site could bypass access rights to change any part of any piece of content. They could also view private information stored in those items.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies to any site where an attacker has the edit in place field editing access right.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Edit in-place field to 2.1.1.
For developers: what the fix changed
The fix adds entity update and field edit access checks in `EditInPlaceFormBase::loadEntity` and updates `processRequest` to retrieve form data from `$form_state` instead of the raw request to prevent tampering.
Also in this release Fixed schema errors and added tests.
config/schema/edit_in_place_field.schema.yml+1 −5src/Form/EditInPlaceFormBase.php+36 −27 fix