{"id":"CVE-2024-13272","title":"Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.","summary":"Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-1220"],"vendor":"paragraphs_table_project","product":"paragraphs_table","affected":["paragraphs_table < 1.23","paragraphs_table >= 2.0.0, < 2.0.2"],"patched":["paragraphs_table 2.0.2"],"published":"2025-01-09","updated":"2026-07-21","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-13272","references":[{"url":"https://www.drupal.org/sa-contrib-2024-036","label":"mlhess@drupal.org"}],"tags":["nvd"],"epss":0.00242,"epssPercentile":0.15621,"ingestedAt":"2026-07-21T14:50:46.513Z","slug":"CVE-2024-13272","body":"## Overview\n\nInsufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.\n\n## Affected\n\n- `paragraphs_table < 1.23`\n- `paragraphs_table >= 2.0.0, < 2.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `paragraphs_table 2.0.2`","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}