// For flags

CVE-2020-13673

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.

El módulo Entity Embed proporciona un filtro para permitir la inserción de entidades en los campos de contenido. En determinadas circunstancias, el filtro podría permitir a un usuario no privilegiado inyectar HTML en una página cuando ésta es accedida por un usuario confiable con permiso para insertar entidades. En algunos casos, esto podría conllevar a un ataque de tipo cross-site scripting

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-05-28 CVE Reserved
  • 2022-02-11 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
-
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
alpha1
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
alpha2
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
alpha3
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
beta1
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
beta2
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
beta3
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
rc1
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.0
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.0"
rc2
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.1
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.1"
-
Affected
Drupal
Search vendor "Drupal"
Entity Embed
Search vendor "Drupal" for product "Entity Embed"
8.x-1.2
Search vendor "Drupal" for product "Entity Embed" and version "8.x-1.2"
-
Affected