QID 730408
Date Published: 2022-03-29
QID 730408: Drupal Core CKEDITOR library Cross-Site Scripting (XSS) Vulnerability (SA-CORE-2022-005)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to an XSS attack.
Affected Versions:
Drupal 9.3.x prior to Drupal 9.3.7
Drupal 9.2.x prior to Drupal 9.2.14
NOTE:
This issue is mitigated by the fact that it only affects sites with CKEditor enabled.
CKEditor 4.18.0 and later include the fix.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation of this vulnerability may allow an attacker to execute attacks related to Cross Site Scripting Vulnerability.
Solution
Customers are advised to install latest drupal version.
For more information visitDrupal security advisory SA-CORE-2022-005
For more information visitDrupal security advisory SA-CORE-2022-005
Vendor References
- SA-CORE-2022-005 -
www.drupal.org/SA-CORE-2022-005
CVEs related to QID 730408
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-005 |
|