CVE-2022-25271
Summary
| CVE | CVE-2022-25271 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-16 23:15:00 UTC |
| Updated | 2022-11-07 14:51:00 UTC |
| Description | Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 36 Update: drupal7-7.92-1.fc36 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: drupal7-7.92-1.fc35 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: drupal7-7.92-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Drupal core - Moderately critical - Improper input validation - SA-CORE-2022-003 | Drupal.org |
CONFIRM |
www.drupal.org |
Patch, Vendor Advisory |
| [SECURITY] Fedora 35 Update: drupal7-7.92-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 154105 Drupal Core Improper Input Validation Vulnerability (SA-CORE-2022-003)
- 283227 Fedora Security Update for drupal7 (FEDORA-2022-9d655503ea)
- 283277 Fedora Security Update for drupal7 (FEDORA-2022-bf18450366)
- 283473 Fedora Security Update for drupal7 (FEDORA-2022-c4334d5277)
- 502055 Alpine Linux Security Update for drupal7
- 504708 Alpine Linux Security Update for drupal7
- 730375 Drupal Core Security Update (SA-CORE-2022-003)