The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.
2022-02-11T16:15:08.250
2024-11-21T05:01:44.220
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:P/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.0 | Yes |
Application | drupal | entity_embed | 8.x-1.1 | Yes |
Application | drupal | entity_embed | 8.x-1.2 | Yes |