drupal/webform_rest is vulnerable to Access bypass
53
Medium Risk
The Webform REST module exposes REST endpoints to retrieve and submit webform submissions, but it does not sufficiently enforce the parent webform's permissions for creating, viewing, or updating submissions. A user who already has permission to use the REST resources can bypass webform-level access controls and interact with submissions they should not be able to access or modify. Exploitation is mitigated because the attacker must already have REST resource permissions.
You are affected if you are using a version that falls within the vulnerable range and have the Webform REST module enabled with REST resources configured.
drupal/webform_rest is vulnerable to Access bypass in versions 0.0.1 - 4.0.3.
Upgrade the drupal/webform_rest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant