Drupal

Drupal

271 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 26.04.2023 19:15:09
  • Zuletzt bearbeitet 03.02.2025 17:15:14

The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. Some sites may require configuration changes following this secur...

  • EPSS 1.24%
  • Veröffentlicht 26.04.2023 15:15:08
  • Zuletzt bearbeitet 03.02.2025 19:15:09

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or oth...

  • EPSS 0.21%
  • Veröffentlicht 26.04.2023 15:15:08
  • Zuletzt bearbeitet 03.02.2025 19:15:09

Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010). However, the protec...

  • EPSS 0.37%
  • Veröffentlicht 26.04.2023 15:15:08
  • Zuletzt bearbeitet 03.02.2025 19:15:09

Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alter data they should not have access to. No forms provided by Drupal core are known to be vulnerable. However, fo...

  • EPSS 0.18%
  • Veröffentlicht 26.04.2023 14:15:09
  • Zuletzt bearbeitet 03.02.2025 20:15:30

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but...

  • EPSS 0.15%
  • Veröffentlicht 26.04.2023 14:15:09
  • Zuletzt bearbeitet 03.02.2025 19:15:08

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content general...

  • EPSS 0.31%
  • Veröffentlicht 26.04.2023 14:15:09
  • Zuletzt bearbeitet 03.02.2025 19:15:09

In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivative images using the image styles system. Access to a non-public file is checked only if it i...

  • EPSS 1.57%
  • Veröffentlicht 28.09.2022 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:54

Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `in...

  • EPSS 0.69%
  • Veröffentlicht 10.06.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:46

Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on ...

  • EPSS 1.46%
  • Veröffentlicht 10.06.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:46

Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we ...