Loading HuntDB...

GHSA-m6q5-wv4x-fv6h

GitHub Security Advisory

Cross-site Scripting in Drupal Core

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

Affected Packages

Packagist drupal/core
Affected versions: 8.0.0 (fixed in 8.8.10)
Packagist drupal/core
Affected versions: 8.9.0 (fixed in 8.9.6)
Packagist drupal/core
Affected versions: 9.0.0 (fixed in 9.0.6)
Packagist drupal/drupal
Affected versions: 8.0.0 (fixed in 8.8.10)
Packagist drupal/drupal
Affected versions: 8.9.0 (fixed in 8.9.6)
Packagist drupal/drupal
Affected versions: 9.0.0 (fixed in 9.0.6)

Related CVEs

Key Information

GHSA ID
GHSA-m6q5-wv4x-fv6h
Published
February 12, 2022 12:00 AM
Last Modified
February 25, 2022 3:33 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
drupal/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.