Miggo Logo

GHSA-vfgc-c76h-mwh4: Drupal core Cross-Site Scripting (XSS) vulnerabilities

5.3

CVSS Score
3.1

Basic Information

CVE ID
-
EPSS Score
-
Published
5/15/2024
Updated
5/15/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
drupal/corecomposer>= 8.0.0, < 8.9.188.9.18
drupal/corecomposer>= 9.1.0, < 9.1.129.1.12
drupal/corecomposer>= 9.2.0, < 9.2.49.2.4

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability stems from Drupal's integration of a vulnerable CKEditor library version rather than specific functions in Drupal core. The advisory indicates the XSS vulnerabilities exist when using outdated CKEditor versions, and the fix involves updating CKEditor via Drupal's dependency management. No specific Drupal core functions are explicitly mentioned in the provided vulnerability details, commit diffs, or patch information. The root cause is the third-party library's vulnerability, not identifiable Drupal functions with high confidence.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

T** *rup*l proj**t us*s t** *K**itor, li*r*ry *or WYSIWY* **itin*. *K**itor **s r*l**s** * s**urity up**t* t**t imp**ts *rup*l. Vuln*r**iliti*s *r* possi*l* i* *rup*l is *on*i*ur** to *llow us* o* t** *K**itor li*r*ry *or WYSIWY* **itin*. *n *tt**k*

Reasoning

T** vuln*r**ility st*ms *rom *rup*l's int**r*tion o* * vuln*r**l* `*K**itor` li*r*ry v*rsion r*t**r t**n sp**i*i* *un*tions in *rup*l *or*. T** **visory in*i**t*s t** XSS vuln*r**iliti*s *xist w**n usin* out**t** `*K**itor` v*rsions, *n* t** *ix invo