vulnerability

FreeBSD: VID-f70ab05e-be06-11eb-b983-000c294bb613 (CVE-2020-13672): drupal7 -- fix possible CSS

Severity
3
CVSS
(AV:N/AC:H/Au:N/C:N/I:P/A:N)
Published
Jun 6, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

Drupal Security team reports: Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. Not all sites and users are affected, but configuration changes to prevent the exploit might be impractical and will vary between sites. Therefore, we recommend all sites update to this release as soon as possible.

Solution

freebsd-upgrade-package-drupal7
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.