CVE-2020-13672

Source
https://cve.org/CVERecord?id=CVE-2020-13672
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13672.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13672
Aliases
Downstream
Published
2022-02-11T16:15:08.190Z
Modified
2026-02-13T02:01:55.675197Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x versions prior to 9.0.12; 8.9.x versions prior to 8.9.14; 7.x versions prior to 7.80.

References

Affected packages

Git / github.com/drupal/drupal

Affected ranges

Affected versions

8.*
8.9.0
8.9.1
8.9.10
8.9.11
8.9.12
8.9.13
8.9.2
8.9.3
8.9.4
8.9.5
8.9.6
8.9.8
8.9.9
9.*
9.0.0
9.0.1
9.0.10
9.0.11
9.0.2
9.0.3
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13672.json"