CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
24.4%
Drupal core’s sanitization API fails to properly filter cross-site scripting under certain circumstances. Not all sites and users are affected, but configuration changes to prevent the exploit might be impractical and will vary between sites. Therefore, we recommend all sites update to this release as soon as possible.
www.drupal.org/project/drupal/releases/7.80
www.drupal.org/project/drupal/releases/8.9.14
www.drupal.org/project/drupal/releases/9.0.12
www.drupal.org/project/drupal/releases/9.1.7
www.drupal.org/user/102818
www.drupal.org/user/157725
www.drupal.org/user/17943
www.drupal.org/user/205645
www.drupal.org/user/255969
www.drupal.org/user/2582268
www.drupal.org/user/3407764
www.drupal.org/user/395439
www.drupal.org/user/49851
www.drupal.org/user/521118
www.drupal.org/user/65776
www.drupal.org/user/78040
www.drupal.org/user/99777
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
24.4%