CVE-2020-13666
Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XS
Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Core 7.x versions prior to 7.73.
8.8.x versions prior to 8.8.10.
8.9.x versions prior to 8.9.6.
9.0.x versions prior to 9.0.6.
MEDIUM · CVSS 6.1
EPSS 0.00509
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0