DRUPAL-CORE-2021-006
Dashboard / Vulnerabilities / DRUPAL-CORE-2021-006
DRUPAL-CORE-2021-006
Summary:
Details: The Drupal core Media module allows embedding internal and external media in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed media. In some cases, this could lead to cross-site scripting. This advisory is not covered by [Drupal Steward](/steward). Also see [Entity Embed - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2021-028](https://www.drupal.org/sa-contrib-2021-028) which addresses a similar vulnerability for that module. *Updated 18:15 UTC to clarify text.*
References: https://www.drupal.org/sa-core-2021-006
Affected packages
Package
Name: drupal/core
Purl: pkg:composer/drupal/core
Affected ranges
Type: ECOSYSTEM
Events:
