CVE-2020-13662: Medium severity drupal vulnerability
Published May 20, 2020
·Updated
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002
Other sources
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.
Affected Software
6 affected componentsFixes available
composer/drupal/drupal>=7.0.0, <7.70, >=8.0.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.4.0, >=8.4.0, <8.5.0, >=8.5.0, <8.6.0, >=8.6.0, <8.7.0, >=8.7.0, <8.7.14, >=8.8.0, <8.8.6
composer/drupal/core>=7.0.0, <7.70, >=8.0.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.4.0, >=8.4.0, <8.5.0, >=8.5.0, <8.6.0, >=8.6.0, <8.7.0, >=8.7.0, <8.7.14, >=8.8.0, <8.8.6
debian/drupal7
composer/drupal/drupal>=7.0.0<7.70
7.70
composer/drupal/core>=7.0.0<7.70
7.70
Drupal Drupal>=7.0<=7.70
Event History
May 20, 2020
Advisory Published
01:37 PM
May 5, 2021
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Drupal core vulnerability?
The vulnerability ID for this Drupal core vulnerability is CVE-2020-13662.
2
What is the severity of CVE-2020-13662?
CVE-2020-13662 is classified as Moderately critical.
3
What is the type of vulnerability in CVE-2020-13662?
CVE-2020-13662 is a Cross Site Scripting (XSS) vulnerability.
4
Which versions of Drupal Core are affected by CVE-2020-13662?
Drupal Core 7 version 7.70 and prior versions are affected by CVE-2020-13662.
5
How can I fix the vulnerability in Drupal Core CVE-2020-13662?
To fix the vulnerability in Drupal Core CVE-2020-13662, you should update Drupal Core to version 7.71 or apply the necessary patches provided by Drupal.