Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versions before 7.73; 8.8.x versions before 8.8.10; 8.9.x versions before 8.9.6; 9.0.x versions before 9.0.6.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
drupal drupal |