First published: Wed Apr 21 2021(Updated: )
Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x versions prior to 9.0.12; 8.9.x versions prior to 8.9.14; 7.x versions prior to 7.80.
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=7.0.0<7.80>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.9.0>=8.9.0<8.9.14>=9.0.0<9.0.12>=9.1.0<9.1.7 | |
composer/drupal/drupal | >=7.0.0<7.80>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.9.0>=8.9.0<8.9.14>=9.0.0<9.0.12>=9.1.0<9.1.7 | |
Drupal Drupal | <7.80 | |
Drupal Drupal | >=8.9.0<8.9.14 | |
Drupal Drupal | >=9.0.0<9.0.12 | |
Drupal Drupal | >=9.1.0<9.1.7 | |
composer/drupal/drupal | >=9.1.0<9.1.7 | 9.1.7 |
composer/drupal/drupal | >=9.0.0<9.0.12 | 9.0.12 |
composer/drupal/drupal | >=8.0.0<8.9.14 | 8.9.14 |
composer/drupal/drupal | >=7.0.0<7.80 | 7.80 |
composer/drupal/core | >=9.1.0<9.1.7 | 9.1.7 |
composer/drupal/core | >=9.0.0<9.0.12 | 9.0.12 |
composer/drupal/core | >=8.0.0<8.9.14 | 8.9.14 |
composer/drupal/core | >=7.0.0<7.80 | 7.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
It is classified as a critical vulnerability.
CVE-2020-13672 is a critical cross-site scripting vulnerability in Drupal core.
Drupal core versions 7.0.0 to 7.80, and 8.0.0 to 8.9.14 are affected by CVE-2020-13672.
The reference for CVE-2020-13672 is https://www.drupal.org/sa-core-2021-002.
To fix CVE-2020-13672, update your Drupal core to version 7.81 or 8.9.15.