Improper Input Validation in Drupal Core Forms Affecting Custom Modules
CVE-2022-25273
7.5HIGH
What is CVE-2022-25273?
An improper input validation vulnerability exists in Drupal Core's form API that can affect contributed or custom modules. This flaw may permit attackers to inject unauthorized values or manipulate data within certain forms, which, although uncommon, could result in the alteration of critical or sensitive information. Properly securing these forms is essential to prevent the exploitation of this vulnerability.
Affected Version(s)
Core 9.3 < 9.3.12
Core 9.2 < 9.2.18