DRUPAL-CONTRIB-2026-059

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/wisski/DRUPAL-CONTRIB-2026-059.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-059
Aliases
  • CVE-2026-13239
Published
2026-06-24T18:40:57Z
Modified
2026-06-24T19:15:04.330003228Z
Summary
[none]
Details

The module adds support for the mirador viewer in WissKI and enables annotations on images via the mirador viewer.

It does not sufficiently check the submitted parameters via a route and writes these to the session object without further checks, which can lead to Access Bypass.

This vulnerability is mitigated by the fact that it is specific to the wisski_mirador submodule.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/wisski

Package

Name
drupal/wisski
Purl
pkg:composer/drupal%2Fwisski

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.0
Database specific
{
    "constraint": "<4.2.0"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/wisski/DRUPAL-CONTRIB-2026-059.json"
affected_versions
"<4.2.0"