{"id":"DRUPAL-CONTRIB-2021-023","details":"This module provides a user interface that allows the implementation and use of *Form modes* without custom development.\n\nThe module does not sufficiently respect access restrictions to entity forms for routes it creates to use specific form modes.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with the permission to use a specific form mode, for example `use X form mode`.","modified":"2026-09-10T03:45:35.016981251Z","published":"2021-07-21T16:51:57Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2021-023"}],"affected":[{"package":{"name":"drupal/form_mode_manager","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/form_mode_manager?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.0"}],"database_specific":{"constraint":"\u003c1.4.0"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/form_mode_manager/DRUPAL-CONTRIB-2021-023.json","affected_versions":"\u003c1.4.0"}}],"schema_version":"1.9.0","credits":[{"name":"Bec","contact":["https://www.drupal.org/user/81067"]},{"name":"Byron Duvall","contact":["https://www.drupal.org/user/1279040"]},{"name":"Jason Partyka","contact":["https://www.drupal.org/user/344048"]}]}