Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 2.0.0 before 2.0.5, from 7.X-1.0 through 7.X-1.5, from 1.0 through 1.2.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
7.x-1.0 (custom)
1.0 (semver)
2.0.0 (semver) before 2.0.5
Credits
Pierre Rudloff (prudloff)
Bálint Nagy (nagy.balint)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
Pierre Rudloff (prudloff)
References
www.drupal.org/sa-contrib-2025-051
www.herodevs.com/vulnerability-directory/cve-2025-47705