GHSA-m648-hpf8-qcjw
Dashboard / Vulnerabilities / GHSA-m648-hpf8-qcjw
GHSA-m648-hpf8-qcjw
Summary: Drupal Core Cross-Site Request Forgery (CSRF) vulnerability
Details: Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-13663, https://github.com/drupal/core/commit/5f3c4d80fd77df0cfa87722b446db54040d55693, https://github.com/drupal/core/commit/bc3235dcb5570bbda62ef9547e7604ee060b72c6, https://github.com/drupal/core/commit/faf3243c4ce03bbaab386af2b272b363fd0dfddb, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2020-13663.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2020-13663.yaml, https://github.com/drupal/core, https://www.drupal.org/sa-core-2020-004
Affected packages
Package
Name: drupal/core
Purl: pkg:composer/drupal/core
Affected ranges
Type: ECOSYSTEM
Events:
