PT-2022-38354 · Packagist · Drupal/Embed

Published

2022-05-25

·

Updated

2022-05-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Drupal Embed module provides a filter to allow embedding various embeddable items like entities in content fields.
In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed items. In some cases, this could lead to Cross-Site Request Forgery.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2022-042

Affected Products

Drupal/Embed