6.1
CVSSv3

CVE-2020-13673

Published: 11/02/2022 Updated: 25/07/2022
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal entity embed 8.x-1.0

drupal entity embed 8.x-1.1

drupal entity embed 8.x-1.2

Vendor Advisories

The Drupal core Media module allows embedding internal and external media in content fields In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed media In some cases, this could lead to cross-site scripting ...