drupal/core is vulnerable to Improper Input Validation
53
Medium Risk
The JSON:API and REST modules validate uploaded image files by checking only the file extension, not the actual MIME type, allowing malicious users to upload non-image files that, depending on web-server configuration, may be served with their real MIME type—potentially leading to XSS or other unintended behavior.
You are affected if you are using a version that falls within the vulnerable range.
drupal/core is vulnerable to Improper Input Validation in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant