An attacker could create a specially crafted url, which could execute arbitrary code in the victim’s browser if loaded. Drupal was not properly sanitizing an exception
This vulnerability affects the following application versions:
- Drupal 8.1.0
- Drupal 8.1.1
- Drupal 8.1.2
- Drupal 8.1.3
- Drupal 8.1.4
- Drupal 8.1.5
- Drupal 8.1.6
- Drupal 8.1.7
- Drupal 8.1.8
- Drupal 8.1.9