QID 154139
Date Published: 2023-05-24
QID 154139: Drupal Core: Improper Input Validation Vulnerability (CVE-2022-25273)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal core's form API has a vulnerability where certain contributed or custom modules forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
Affected Versions:
Drupal from 8.0.0 to 9.2.18
Drupal from 9.3.0 to 9.3.11
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
This vulnerability could allow an attacker to inject disallowed values or overwrite data.
Solution
Customers are advised to install latest Drupal version.
For more information visit Drupal security advisory SA-CORE-2022-008.
For more information visit Drupal security advisory SA-CORE-2022-008.
Vendor References
- SA-CORE-2022-008 -
www.drupal.org/sa-core-2022-008
CVEs related to QID 154139
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-008 |
|