CVE-2020-13673

The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.
References
Link Resource
https://www.drupal.org/sa-contrib-2021-028 Patch Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drupal:entity_embed:8.x-1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:beta3:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.0:-:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:entity_embed:8.x-1.2:*:*:*:*:*:*:*

Information

Published : 2022-02-11 08:15

Updated : 2022-07-25 03:26


NVD link : CVE-2020-13673

Mitre link : CVE-2020-13673


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

drupal

  • entity_embed