CVE-2024-13273

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
drupalCNA
---
---
CISA-ADPADP
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
getopensocialopen_social
𝑥
< 12.3.8
getopensocialopen_social
12.4.0 ≤
𝑥
< 12.4.5
getopensocialopen_social
13.0.0:alpha1
getopensocialopen_social
13.0.0:alpha10
getopensocialopen_social
13.0.0:alpha2
getopensocialopen_social
13.0.0:alpha3
getopensocialopen_social
13.0.0:alpha4
getopensocialopen_social
13.0.0:alpha5
getopensocialopen_social
13.0.0:alpha6
getopensocialopen_social
13.0.0:alpha7
getopensocialopen_social
13.0.0:alpha8
getopensocialopen_social
13.0.0:alpha9
𝑥
= Vulnerable software versions