First published: Wed May 20 2020(Updated: )
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/drupal | >=7.0.0<7.70>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.7.14>=8.8.0<8.8.6 | |
composer/drupal/core | >=7.0.0<7.70>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.7.14>=8.8.0<8.8.6 | |
debian/drupal7 | ||
Drupal Drupal | >=7.0<=7.70 | |
composer/drupal/drupal | >=7.0.0<7.70 | 7.70 |
composer/drupal/core | >=7.0.0<7.70 | 7.70 |
>=7.0<=7.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Drupal core vulnerability is CVE-2020-13662.
CVE-2020-13662 is classified as Moderately critical.
CVE-2020-13662 is a Cross Site Scripting (XSS) vulnerability.
Drupal Core 7 version 7.70 and prior versions are affected by CVE-2020-13662.
To fix the vulnerability in Drupal Core CVE-2020-13662, you should update Drupal Core to version 7.71 or apply the necessary patches provided by Drupal.