Vulnerability Bulletins

Drupal core - Moderately critical - Improper input validation - SA-CORE-2022-003


System information

   
Affected software Drupal

Description

Project: Drupal coreDate: 2022-February-16Security risk: Moderately critical 14∕25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Improper input validationCVE IDs: CVE-2022-25271Description: Drupal cores form API has a vulnerability where certain contributed or custom modules forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an

More info:

https://www.drupal.org/sa-core-2022-003

Standar resources

Property Value
CVE CVE-2022-25271.

Version history

Version Comments Date
1.0 Advisory issued 2022-05-26
Ministerio de Defensa
CNI
CCN
CCN-CERT