2.6 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:N/C:N/I:P/A:N
0.967 High
EPSS
Percentile
99.7%
This module enables you to integrate with amoCRM service using webhooks.
The module does not sufficiently sanitize the logged data when malicious POST data is received.
This vulnerability is mitigated by the fact that a module such “Database logging” (dblog) must be enabled which displays log messages in a HTML context.
Drupal core is not affected. If you do not use the contributed amoCRM module, there is nothing you need to do.
Install the latest version:
Also see the amoCRM project page.
twitter.com/drupalsecurity
www.drupal.org/contact
www.drupal.org/node/2569243
www.drupal.org/project/amocrm
www.drupal.org/security-team
www.drupal.org/security-team/risk-levels
www.drupal.org/security/secure-configuration
www.drupal.org/user/1945174
www.drupal.org/user/262198
www.drupal.org/writing-secure-code