PT-2020-13649 · Drupal · Drupal Core

Alejandro Garza

+5

·

Published

2020-09-16

·

Updated

2024-03-06

·

CVE-2020-13668

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Core versions prior to 8.8.10 Drupal Core versions prior to 8.9.6 Drupal Core versions prior to 9.0.6
Description The issue is related to an Access Bypass vulnerability in Drupal Core, where an attacker can exploit the way HTML is rendered for affected forms.
Recommendations For versions prior to 8.8.10, update to version 8.8.10 or later. For versions prior to 8.9.6, update to version 8.9.6 or later. For versions prior to 9.0.6, update to version 9.0.6 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DRUPAL-2020-13668
CVE-2020-13668
GHSA-M6Q5-WV4X-FV6H

Affected Products

Drupal Core