QID 154118
Date Published: 2022-07-14
QID 154118: Drupal Core Cross-Site Scripting (XSS) Vulnerability (CVE-2021-41182)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
jQuery UI is a third-party library used by Drupal. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). When accepting the value of various Text options of the Datepicker widget from untrusted sources it may lead to execution of untrusted code
Affected Versions:
Drupal 7.0 to 7.86
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
Solution
Customers are advised to install latest Drupal version.
For more information visit Drupal security advisory SA-CORE-2022-002.
For more information visit Drupal security advisory SA-CORE-2022-002.
Vendor References
- SA-CONTRIB-2022-004 -
www.drupal.org/sa-contrib-2022-004
CVEs related to QID 154118
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CONTRIB-2022-004 |
|