QID 154140
Date Published: 2023-05-24
QID 154140: Drupal Core: Cross Site Scripting Vulnerability (CVE-2022-25276)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.
Affected Versions:
Drupal from 9.3.0 to 9.3.18
Drupal from 9.4.0 to 9.4.2
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation would lead attackers to inject HTML or JavaScript via a cross-site scripting, which can help the attacker carry out further attacks and obtain sensitive information.
For more information visit Drupal security advisory SA-CORE-2022-015.
- SA-CORE-2022-015 -
www.drupal.org/sa-core-2022-015
CVEs related to QID 154140
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-015 |
|