QID 154105

Date Published: 2022-03-30

QID 154105: Drupal Core Improper Input Validation Vulnerability (SA-CORE-2022-003)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

Affected versions of this package are vulnerable to Improper Input Validation via certain forms in the form API. This can be abused by injecting or overwriting data.

Affected Versions:
Drupal 7.0.0 to 7.88
Drupal 9.2.0 to 9.2.13
Drupal 9.3.0 to 9.3.6

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.

This vulnerability could allow an attacker to inject disallowed values or overwrite data.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to install latest Drupal version.
    For more information visit Drupal security advisory SA-CORE-2022-003.
    Vendor References

    CVEs related to QID 154105

    Software Advisories
    Advisory ID Software Component Link
    SA-CORE-2022-003 URL Logo www.drupal.org/sa-core-2022-003