HIGH
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation
Published Feb 16, 2022
7.5
HIGHCVSS 3.1
EPSS 1.28%
Description
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
Affected products
-
Affected
- ≥ 7.x, < 7.88
- ≥ 9.2.x, < 9.2.13
- ≥ 9.3.x, < 9.3.6
Configuration 1
Configuration 2
OR
- 35
- 36
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0984 Advisory
- https://github.com/advisories/GHSA-fmfv-x8mp-5767 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
- https://nvd.nist.gov/vuln/detail/CVE-2022-25271
- https://www.drupal.org/sa-core-2022-003 PatchVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner drupal
Published Feb 16, 2022
Updated Aug 3, 2024
Reserved Feb 16, 2022
Link CVE-2022-25271
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-FMFV-X8MP-5767