Input validation error in Drupal - CVE-2022-25271
Published: February 16, 2022 / Updated: February 17, 2022
Vulnerability identifier: #VU60672
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25271
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the web application.
The vulnerability exists due to insufficient validation of user-supplied input within the form API. A remote attacker can send specially crafted input to the Drupal core's form API and inject or overwrite data.
Affected software
Drupal
Backdrop CMS
Fedora
drupal7
Backdrop CMS
Fedora
drupal7
How to mitigate CVE-2022-25271
Install updates from vendor's website.
Drupal - addressed in versions 7.88, 9.2.13, 9.3.6
Backdrop CMS - addressed in versions 1.20.5, 1.21.2
drupal7 - addressed in versions 7.92-1.el7, 7.92-1.fc35, 7.92-1.fc36, 7.92-1.fc37
Backdrop CMS - addressed in versions 1.20.5, 1.21.2
drupal7 - addressed in versions 7.92-1.el7, 7.92-1.fc35, 7.92-1.fc36, 7.92-1.fc37