CVE-2017-6927Cross-site Scripting in Drupal

CWE-79Cross-site Scripting10 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
1.4%
top 19.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 14

Description

Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically go through Twig autoescaping). This function does not correctly handle all methods of injecting malicious HTML, leading to a cross-site scripting vulnerability under certain circumstances. The PHP functions which Drupal provides for HTML escaping are not affecte

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Packagistdrupal/core8.4.08.4.5+1
NVDdrupal/drupal7.07.57+1
Packagistdrupal/drupal8.4.08.4.5+1
CVEListV5drupal.org/drupal_core8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57

Also affects: Debian Linux 7.0, 8.0, 9.0

🔴Vulnerability Details

4
OSV
Drupal cross-site scripting vulnerability2022-05-14
GHSA
Drupal cross-site scripting vulnerability2022-05-14
OSV
CVE-2017-6927: Drupal 82018-03-01
CVEList
CVE-2017-6927: Drupal 82018-03-01

📋Vendor Advisories

1
Drupal
Drupal core - Critical - Multiple Vulnerabilities - SA-CORE-2018-0012018-02-21

💬Community

4
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001)2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal8: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [epel-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
CVE-2017-6927 — Cross-site Scripting in Drupal | cvebase