Closed (fixed)
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
15 Jan 2026 at 19:06 UTC
Updated:
18 Feb 2026 at 20:29 UTC
Jump to comment: Most recent
Comments
Comment #3
gregglesComment #5
elc commentedAgree these look good for CAS Server:
CWE 91 XML Injection (aka Blind XPath Injection)
CAPEC 233 Privilege Escalation
I've not had a chance to look at the others.
Comment #6
penyaskitoNot very familiar with CWE or CAPEC so there might be better choices, but from the little I know Canvas SA-contrib-2026-006 LGTM 👍🏽
Comment #9
gregglesThese are now filed.
Thanks for the help, @elc and @penyaskito!
Comment #11
gregglesAnd poker10 - thanks for your help as well :)