Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Remediation
References
Related Vulnerabilities
Python Untrusted Search Path Vulnerability (CVE-2008-5983)
WordPress Plugin Twitter Feed:Embedded Timeline 'url' Parameter Cross-Site Scripting (0.3.1)
MySQL CVE-2012-1689 Vulnerability (CVE-2012-1689)
Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.7)
Microsoft SQL Server Remote Code Execution Vulnerability (CVE-2020-0618)