Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
0.0.0 (semver) before 1.13.0
3.0.0 (semver) before 3.0.4
Credits
Mitch Portier (arkener)
Elijah Byrd (elibyrd)
Mitch Portier (arkener)
Joseph Olstad (joseph.olstad)
Ivo Van Geertruyen (mr.baileys)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2025-042