Vulnerability Description
Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | >= 8.8.0, < 8.8.10 |
Related Weaknesses (CWE)
References
- https://www.drupal.org/sa-core-2020-009PatchVendor Advisory
- https://www.drupal.org/sa-core-2020-009PatchVendor Advisory
FAQ
What is CVE-2020-13668?
CVE-2020-13668 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8....
How severe is CVE-2020-13668?
CVE-2020-13668 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13668?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Drupal.