QID 154117

Date Published: 2022-07-14

QID 154117: Drupal Core Cross-Site Scripting (XSS) Vulnerability (SA-CORE-2022-002)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

jQuery UI is a third-party library used by Drupal. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). When accepting the value of various Text options of the Datepicker widget from untrusted sources it may lead to execution of untrusted code

Affected Versions:
Drupal 7.0 to 7.86
Drupal 9.2.0 to 9.2.11
Drupal 9.3.0 to 9.3.3

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.

Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to install latest Drupal version.
    For more information visit Drupal security advisory SA-CORE-2022-002.
    Vendor References

    CVEs related to QID 154117

    Software Advisories
    Advisory ID Software Component Link
    sa-core-2022-002 URL Logo www.drupal.org/sa-core-2022-002