PT-2024-9339 · Drupal · Drupal Core

Benji Fisher

+7

·

Published

2024-11-20

·

Updated

2025-06-03

·

CVE-2024-12393

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Drupal Core versions 8.8.0 through 10.2.11 Drupal Core versions 10.3.0 through 10.3.9 Drupal Core versions 11.0.0 through 11.0.8
Description: The issue is related to insufficient protection of the web page structure, allowing an attacker to conduct a cross-site scripting (XSS) attack. This is due to improper neutralization of input during web page generation, which enables cross-site scripting. The problem affects Drupal Core, allowing attackers to exploit this flaw and leading to XSS.
Recommendations: For Drupal Core versions 8.8.0 through 10.2.11, update to version 10.2.11 or later. For Drupal Core versions 10.3.0 through 10.3.9, update to version 10.3.9 or later. For Drupal Core versions 11.0.0 through 11.0.8, update to version 11.0.8 or later. As a temporary workaround, consider restricting the use of JavaScript to render status messages in certain cases and configurations to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-11029
BIT-DRUPAL-2024-12393
CVE-2024-12393
DRUPAL-CORE-2024-003
GHSA-8MVQ-8H2V-J9VF

Affected Products

Drupal Core