First published: Wed Jun 17 2020(Updated: )
Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=7.0.0<7.72>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.8>=8.9.0<8.9.1>=9.0.0<9.0.1 | |
composer/drupal/drupal | >=7.0.0<7.72>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.8>=8.9.0<8.9.1>=9.0.0<9.0.1 | |
composer/drupal/drupal | >=9.0.0<9.0.1 | 9.0.1 |
composer/drupal/drupal | >=8.9.0<8.9.1 | 8.9.1 |
composer/drupal/drupal | >=8.0.0<8.8.8 | 8.8.8 |
composer/drupal/drupal | >=7.0.0<7.72 | 7.72 |
composer/drupal/core | >=8.0.0<8.8.8 | 8.8.8 |
composer/drupal/core | >=7.0.0<7.72 | 7.72 |
composer/drupal/core | >=9.0.0<9.0.1 | 9.0.1 |
composer/drupal/core | >=8.9.0<8.9.1 | 8.9.1 |
Drupal | >=7.0<7.72 | |
Drupal | >=8.8.0<8.8.8 | |
Drupal | >=8.9.0<8.9.1 | |
Drupal | >=9.0.0<9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13663 is classified as a Critical Cross Site Request Forgery vulnerability in Drupal.
To fix CVE-2020-13663, you should upgrade your Drupal installation to versions 7.72, 8.8.8, 8.9.1, or 9.0.1.
CVE-2020-13663 affects Drupal versions 7.0.0 to 7.71, 8.0.0 to 8.1.0, 8.1.0 to 8.2.0, 8.2.0 to 8.3.0, 8.3.0 to 8.4.0, 8.4.0 to 8.5.0, 8.5.0 to 8.6.0, 8.6.0 to 8.7.0, 8.7.0 to 8.8.0, 8.8.0 to 8.8.8, 8.9.0 to 8.9.1, and 9.0.0 to 9.0.1.
CVE-2020-13663 is a Cross Site Request Forgery (CSRF) vulnerability in the Drupal Core Form API.
If exploited, CVE-2020-13663 can lead to unauthorized actions being performed through cross-site requests, potentially leading to further vulnerabilities.