Back

HIGH

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation

Published Feb 16, 2022

Description

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner drupal
Published Feb 16, 2022
Updated Aug 3, 2024
Reserved Feb 16, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner drupal
Published Feb 16, 2022
Updated Aug 3, 2024