CVE-2024-12393
10.12.2024, 00:15
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
Vendor | Product | Version |
---|---|---|
drupal | drupal | 8.8.0 ≤ 𝑥 < 10.2.11 |
drupal | drupal | 10.3.0 ≤ 𝑥 < 10.3.9 |
drupal | drupal | 11.0.0 ≤ 𝑥 < 11.0.8 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References