DRUPAL-CONTRIB-2023-047

    Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2023-047

    DRUPAL-CONTRIB-2023-047

    Published: 27 Sept 2023Last Modified: 10 Sept 2026

    Summary:

    Details: This module enables notifications to be sent to all users of a particular role, or to the content's author when a piece of content is transitioned from one state to another via core's content\_moderation module. The module doesn't sufficiently check access to content when sending notifications. This vulnerability is mitigated by the fact that an attacker must have been assigned to receive notifications for the given content. Additionally, only data sent in the email is visible, so the attacker cannot access the content on the site.

    Affected packages

    Package

    Name: drupal/content_moderation_notifications

    Purl: pkg:composer/drupal/content_moderation_notifications?repository_url=https:%2F%2Fpackages.drupal.org%2F8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.0.0
    Fixed -3.6.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DRUPAL-CONTRIB-2023-047 | CVE-DB