Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-6927
Description:Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically go through Twig autoescaping). This function does not correctly handle all methods of injecting malicious HTML, leading to a cross-site scripting vulnerability under certain circumstances. The PHP functions which Drupal provides for HTML escaping are not affected.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-6927
BugTraq ID: 103138
http://www.securityfocus.com/bid/103138
Debian Security Information: DSA-4123 (Google Search)
https://www.debian.org/security/2018/dsa-4123
https://lists.debian.org/debian-lts-announce/2018/02/msg00030.html




© 1998-2024 E-Soft Inc. All rights reserved.