{"id":"DRUPAL-CONTRIB-2019-060","details":"This module provides an autocomplete widget for text fields that suggests all existing (previously entered) values for that field.\n\nThe module doesn't sufficiently check for proper access permission before returning autocomplete results.\n\nThis vulnerability is mitigated by the fact that an attacker must know the route to the autocomplete callback controller though this is easily known.","modified":"2026-09-10T03:45:44.471895765Z","published":"2019-07-24T17:36:23Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2019-060"}],"affected":[{"package":{"name":"drupal/existing_values_autocomplete_widget","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/existing_values_autocomplete_widget?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.0"}],"database_specific":{"constraint":"\u003c1.2.0"}}],"database_specific":{"affected_versions":"\u003c1.2.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/existing_values_autocomplete_widget/DRUPAL-CONTRIB-2019-060.json"}}],"schema_version":"1.9.0","credits":[{"name":"David Stinemetze","contact":["https://www.drupal.org/user/2508346"]}]}