CVE-2025-13979
EUVD-2025-20644228.01.2026, 20:16
Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| salsa.digital | mini_site | 𝑥 < 3.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-267 - Privilege Defined With Unsafe ActionsA particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.