PT-2025-15240 · Unknown · Tarteaucitron.Js

Pierre Rudloff

+1

·

Published

2025-04-07

·

Updated

2025-06-12

·

CVE-2025-31476

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions tarteaucitron.js versions prior to 1.20.1
Description A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges to enter a URL containing an insecure scheme, such as javascript:alert(). Insufficient URL validation could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior.
Recommendations For versions prior to 1.20.1, update to version 1.20.1 to fix the vulnerability. As a temporary workaround, consider restricting access to the URL validation function to minimize the risk of exploitation. Avoid using insecure URL schemes in links until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-31476
DRUPAL-CONTRIB-2025-027
GHSA-P5G4-V748-6FH8

Affected Products

Tarteaucitron.Js