PT-2020-6778 · Drupal · Drupal Core

Dor Tumarkin

+1

·

Published

2020-06-17

·

Updated

2024-03-06

·

CVE-2020-13663

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Drupal Core (affected versions not specified)
Description The issue is related to insufficient authentication of executed requests in the Drupal CMS system. It can be exploited by a remote attacker to execute arbitrary code. Additionally, there is a Cross Site Request Forgery vulnerability in the Drupal Core Form API, which does not properly handle certain form input from cross-site requests, potentially leading to other vulnerabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

BDU:2022-06302
BIT-DRUPAL-2020-13663
CVE-2020-13663
DLA-2263-1
DRUPAL-CORE-2020-004
DSA-4706-1
GHSA-M648-HPF8-QCJW

Affected Products

Drupal Core