Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
0.0.0 (semver) before 12.3.8
12.4.0 (semver) before 12.4.5
Credits
Thiago Régis
Thiago Régis
Ronald te Brake
Greg Knaddison
Juraj Nemec
References
www.drupal.org/sa-contrib-2024-037