vulnerability

Drupal: CVE-2020-13663: Drupal core - Critical - Cross Site Request Forgery - SA-CORE-2020-004

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jun 18, 2020
Added
Jun 18, 2020
Modified
Jun 23, 2021

Description

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.

Solution(s)

drupal-upgrade-7_72drupal-upgrade-8_8_8drupal-upgrade-8_9_1drupal-upgrade-9_0_1
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.