Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Drupal 7.x, 8.x, 9.x XSS Vulnerability (SA-CORE-2020-007) (Linux)
Information
Severity
Severity
Medium
Family
Family
Web application abuses
CVSSv2 Base
CVSSv2 Base
5.5
CVSSv2 Vector
CVSSv2 Vector
AV:N/AC:L/Au:S/C:P/I:P/A:N
Solution Type
Solution Type
Vendor Patch
Created
Created
3 years ago
Modified
Modified
3 years ago
Summary
Drupal is prone to a cross-site scripting vulnerability.
Insight
Insight
The Drupal AJAX API does not disable JSONP by default, which can lead to cross-site scripting.
Affected Software
Affected Software
Drupal 7.x, 8.8.x and prior, 8.9.x and 9.0.x.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Update to version 7.73, 8.8.10, 8.9.6, 9.0.6 or later.