MEDIUM
The Entity Embed module provides a filter to allow embedding entities in content fields
Published Feb 11, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.26%
Description
The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.
Affected products
-
Affected
- ≥ 8.x, < 8.x-1.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Drupal | Entity Embed | unknown | Affected
|
OR
- 8.x-1.0
- 8.x-1.0
- 8.x-1.0
- 8.x-1.0
- 8.x-1.0
- 8.x-1.0
- 8.x-1.0
- 8.x-1.0
- 8.x-1.0
- 8.x-1.1
- 8.x-1.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-5903 Advisory
- https://www.drupal.org/sa-contrib-2021-028 x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-5903 | Advisory | |
| https://www.drupal.org/sa-contrib-2021-028 | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner drupal
Published Feb 11, 2022
Updated Aug 4, 2024
Reserved May 28, 2020
Link CVE-2020-13673
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data