QID 730408

Date Published: 2022-03-29

QID 730408: Drupal Core CKEDITOR library Cross-Site Scripting (XSS) Vulnerability (SA-CORE-2022-005)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to an XSS attack.

Affected Versions:
Drupal 9.3.x prior to Drupal 9.3.7
Drupal 9.2.x prior to Drupal 9.2.14

NOTE:
This issue is mitigated by the fact that it only affects sites with CKEditor enabled.
CKEditor 4.18.0 and later include the fix.

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.

Successful exploitation of this vulnerability may allow an attacker to execute attacks related to Cross Site Scripting Vulnerability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to install latest drupal version.
    For more information visitDrupal security advisory SA-CORE-2022-005

    Vendor References

    CVEs related to QID 730408

    Software Advisories
    Advisory ID Software Component Link
    SA-CORE-2022-005 URL Logo www.drupal.org/SA-CORE-2022-005