5.4

CVE-2024-13273

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetopensocialOpen Social SwPlatformdrupal Version < 12.3.8
GetopensocialOpen Social SwPlatformdrupal Version >= 12.4.0 < 12.4.5
GetopensocialOpen Social Version13.0.0 Updatealpha1 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha10 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha2 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha3 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha4 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha5 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha6 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha7 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha8 SwPlatformdrupal
GetopensocialOpen Social Version13.0.0 Updatealpha9 SwPlatformdrupal
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.381
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.