Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple multi step form allows Cross-Site Scripting (XSS).This issue affects Simple multi step form: from 0.0.0 before 2.0.0.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")
Product status
0.0.0 (semver) before 2.0.0
Credits
Ide Braakman (idebr)
Diosbel MezquÃa (dmezquia)
Ide Braakman (idebr)
Vitaliy Bogomazyuk (vitaliyb98)
Greg Knaddison (greggles)
Ivo Van Geertruyen (mr.baileys)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2025-116