QID 730106
Date Published: 2021-06-10
QID 730106: Drupal Core CKEDITOR library XSS Vulnerability (SA-CORE-2021-003)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to an XSS attack.
Affected Versions:
Drupal 9.1.x prior to Drupal 9.1.9
Drupal 9.0.x prior to Drupal 9.0.14
Drupal 8.9.x prior to Drupal 8.9.16
NOTE:
This issue is mitigated by the fact that it only affects sites with CKEditor enabled.
CKEditor 4.16.1 and later include the fix.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation of this vulnerability may allow an attacker to execute attacks related to Cross Site Scripting Vulnerability.
For more information visitDrupal security advisory SA-CORE-2021-003
- SA-CORE-2021-003 -
www.drupal.org/sa-core-2021-003
CVEs related to QID 730106
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2021-003 |
|