PT-2023-12781 · Drupal · Drupal

Dezső Biczó

·

Published

2023-04-26

·

Updated

2025-02-03

·

CVE-2022-25273

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Drupal core versions prior to the fixed version
Description The form API in Drupal core has a vulnerability that affects certain contributed or custom modules' forms, making them susceptible to improper input validation. This could allow an attacker to inject disallowed values or overwrite data, potentially altering critical or sensitive data in uncommon but certain cases.
Recommendations For versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to affected forms until a patch is available. Avoid using contributed or custom modules that may be vulnerable to improper input validation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BIT-DRUPAL-2022-25273
CVE-2022-25273
DRUPAL-CORE-2022-008
GHSA-G36H-4JR6-QMM9

Affected Products

Drupal