mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
18 lines
772 B
Markdown
18 lines
772 B
Markdown
### [CVE-2022-25276](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25276)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.drupal.org/sa-core-2022-015
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|