Field API Pane Editor (FAPE) - Moderately Critical - Access Bypass
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-1.3
The Field API Pane Editor module exposed its field edit route to all users, including anonymous users, by omitting a proper access callback. An attacker could reach the field edit controller without authentication, though secondary entity and field access checks within the controller still limited practical exploitation.