GHSA-m6q5-wv4x-fv6h
GitHub Security Advisory
Cross-site Scripting in Drupal Core
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
Affected Packages
Packagist
drupal/core
Affected versions:
8.0.0
(fixed in 8.8.10)
Packagist
drupal/core
Affected versions:
8.9.0
(fixed in 8.9.6)
Packagist
drupal/core
Affected versions:
9.0.0
(fixed in 9.0.6)
Packagist
drupal/drupal
Affected versions:
8.0.0
(fixed in 8.8.10)
Packagist
drupal/drupal
Affected versions:
8.9.0
(fixed in 8.9.6)
Packagist
drupal/drupal
Affected versions:
9.0.0
(fixed in 9.0.6)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.