CWE
79
Advisory Published
Advisory Published
Updated

CVE-2022-25276: XSS

First published: Wed Apr 26 2023(Updated: )

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities. Drupal 7 core does not include the Media module and therefore is not affected.

Credit: mlhess@drupal.org mlhess@drupal.org

Affected SoftwareAffected VersionHow to fix
Drupal Drupal>=9.3.0<9.3.19
Drupal Drupal>=9.4.0<9.4.3
composer/drupal/core>=9.4.0<9.4.3
9.4.3
composer/drupal/core>=8.0.0<9.3.19
9.3.19

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-25276?

    The severity of CVE-2022-25276 is medium.

  • How does CVE-2022-25276 affect Drupal?

    CVE-2022-25276 affects Drupal versions 9.3.0 to 9.3.19 and 9.4.0 to 9.4.3.

  • What can happen if CVE-2022-25276 is exploited?

    Exploiting CVE-2022-25276 can lead to cross-site scripting, leaked cookies, or other vulnerabilities.

  • How can I fix CVE-2022-25276 in Drupal?

    To fix CVE-2022-25276 in Drupal, update to version 9.4.3 if you're using versions 9.4.0 to 9.4.2, or update to version 9.3.19 if you're using versions 9.3.0 to 9.3.18.

  • Where can I find more information about CVE-2022-25276?

    You can find more information about CVE-2022-25276 on the NIST National Vulnerability Database (NVD), Drupal Security Advisory, and GitHub Advisories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203