Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-25273: Drupal core - Moderately critical - Improper input validation - SA-CORE-2022-008

Drupal core’s form API has a vulnerability where certain contributed or custom modules’ forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.

CVE
#vulnerability

Vulnerability:

Improper input validation

Affected versions:

>= 8.0.0 <9.2.18 || >= 9.3.0 <9.3.12

Description:

Drupal core’s form API has a vulnerability where certain contributed or custom modules’ forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.

We do not know of affected forms within core itself, but contributed and custom project forms could be affected. Installing this update will fix those forms.

This advisory is not covered by Drupal Steward.

Fixed By:

  • xjm of the Drupal Security Team
  • Alex Bronstein of the Drupal Security Team
  • Dezső BICZÓ
  • Lee Rowlands of the Drupal Security Team

Related news

GHSA-g36h-4jr6-qmm9: Improper input validation in Drupal core

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data. Drupal 7 is not affected.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda