CVE-2024-12393

Severity
5.4MEDIUM
EPSS
1.9%
top 16.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages5 packages

Packagistdrupal/core8.8.010.2.11+2
CVEListV5drupal/drupal_core8.8.010.2.11+2
Packagistdrupal/core-recommended8.8.010.2.11+2
NVDdrupal/drupal8.8.010.2.11+2
Packagistdrupal/drupal8.8.010.2.11+2

🔴Vulnerability Details

5
OSV
CVE-2024-12393: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (2024-12-10
OSV
Drupal Core Cross-Site Scripting (XSS)2024-12-10
GHSA
Drupal Core Cross-Site Scripting (XSS)2024-12-10
CVEList
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-0032024-12-09
OSV
CVE-2024-12393: Drupal uses JavaScript to render status messages in some cases and configurations2024-11-20

📋Vendor Advisories

1
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-0032024-11-20
CVE-2024-12393 (MEDIUM CVSS 5.4) | Improper Neutralization of Input Du | cvebase.io