QID 730455
Date Published: 2022-04-26
QID 730455: Drupal Core Improper Input Validation Vulnerability (SA-CORE-2022-008)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
Affected Versions:
Drupal versions from 9.3.x prior to Drupal 9.3.12
Drupal versions from 9.2.x prior to Drupal 9.2.18
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Successful exploitation of these vulnerability may allow an attacker to alter unauthorized sensitive data.
For more information visitDrupal security advisory sa-core-2022-008
- SA-CORE-2022-008 -
www.drupal.org/sa-core-2022-008
CVEs related to QID 730455
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2022-008 |
|