QID 154126
Date Published: 2022-11-02
QID 154126: Drupal Core: CKEditor Library Multiple Vulnerabilities (CVE-2022-24728,CVE-2022-24729)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
The Drupal project uses the CKEditor library for WYSIWYG editing.
CKEditor has released a security update that impacts Drupal.
CVE-2022-24728: HTML processing vulnerability allowing to execute JavaScript code
CVE-2022-24729: Regular expression Denial of Service in dialog plugin.
Affected Versions:
Drupal 8.0.0 to 9.2.15
Drupal 9.3.0 to 9.3.8
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or significant performance drop resulting in a browser tab freeze.
For more information visit Drupal security advisory SA-CORE-2022-005.
- SA-CORE-2022-005 -
www.drupal.org/sa-core-2022-005
CVEs related to QID 154126
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-005 |
|