First published: Fri Jun 11 2021(Updated: )
Cross-site scripting vulnerability in Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | >=8.8.0<8.8.10 | |
Drupal Drupal | >=8.9.0<8.9.6 | |
Drupal Drupal | >=9.0.0<9.0.6 | |
composer/drupal/core | >=9.0.0<9.0.6 | 9.0.6 |
composer/drupal/core | >=8.9.0<8.9.6 | 8.9.6 |
composer/drupal/core | >=8.8.0<8.8.10 | 8.8.10 |
>=8.8.0<8.8.10 | ||
>=8.9.0<8.9.6 | ||
>=9.0.0<9.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13688 is a cross-site scripting (XSS) vulnerability in Drupal Core.
CVE-2020-13688 affects Drupal Core versions 8.8.X prior to 8.8.10, 8.9.X prior to 8.9.6, and 9.0.X prior to 9.0.6.
The severity of CVE-2020-13688 is medium with a CVSS score of 6.1.
An attacker could exploit CVE-2020-13688 by leveraging the way HTML is rendered for affected forms in Drupal to perform cross-site scripting attacks.
To fix CVE-2020-13688, users should upgrade to Drupal Core versions 8.8.10, 8.9.6, or 9.0.6, which contain the necessary security patches.