PT-2020-6899 · Drupal · Drupal Core

Dor Tumarkin

·

Published

2020-09-16

·

Updated

2024-03-06

·

CVE-2020-13669

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Core versions 8.8.x prior to 8.8.10 Drupal Core versions 8.9.x prior to 8.9.6 Drupal Core versions 9.0.x prior to 9.0.6
Description The issue is related to a Cross-site Scripting (XSS) vulnerability in the ckeditor of Drupal Core, allowing an attacker to inject XSS. This vulnerability can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations For Drupal Core versions 8.8.x prior to 8.8.10, update to version 8.8.10 or later. For Drupal Core versions 8.9.x prior to 8.9.6, update to version 8.9.6 or later. For Drupal Core versions 9.0.x prior to 9.0.6, update to version 9.0.6 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-05261
BIT-DRUPAL-2020-13669
CVE-2020-13669
DRUPAL-CORE-2020-010
GHSA-C533-C843-67H8

Affected Products

Drupal Core