xjm · Jun 28, 2025
"Anemone": The brief tale of a Drupal core security advisory
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
"Anemone": The brief tale of a Drupal core security advisory xjm Sat, 06/28/2025 - 15:03 A long while back, security researcher Sam Mortenson reported a cross-site scripting vulnerability in Drupal core's Link module. Essentially, the options property on link fields was not being properly sanitized. This meant cross-site scripting was possible under some circumstances -- and, as always for…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.