CVE-2022-25271

HIGH

Drupal 7.0.0-7.87 and 9.3.0-9.3.5 - Improper Input Validation in Form API

Title source: llm
STIX 2.1

Description

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 57.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (4)
drupal/core 9.3.0 - 9.3.6Packagist
drupal/drupal 7.0.0 - 7.88
fedoraproject/fedora 35
fedoraproject/fedora 36
Published Feb 16, 2022
Tracked Since Feb 18, 2026