Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Caroline Boyden

#46444of 53,634
5.5Total CVSS
Vulnerabilities · 1
PT-2025-1041
5.5
2025-01-09
Drupal · File Entity · CVE-2024-13237
**Name of the Vulnerable Software and Affected Versions** File Entity versions 7.X-* through 7.X-2.38 **Description** The issue is related to improper neutralization of input during web page generation, allowing Cross-Site Scripting (XSS) attacks. This can enable a remote attacker to bypass security restrictions and conduct Cross-Site Scripting attacks. **Recommendations** For versions 7.X-* through 7.X-2.38, update to a version newer than 7.X-2.38 to resolve the issue. As a temporary workaround, consider restricting access to the File Entity module to minimize the risk of exploitation.