CVE-2024-12393: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003
Drupal uses JavaScript to render status messages in some cases and configurations. In certain situations, the status messages are not adequately sanitized. This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
Other sources
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12393?
CVE-2024-12393 has a moderate severity rating due to the potential for improper input handling.
How do I fix CVE-2024-12393?
To fix CVE-2024-12393, upgrade your Drupal installation to versions 10.2.11, 10.3.9, or 11.0.8.
Which Drupal versions are affected by CVE-2024-12393?
CVE-2024-12393 affects Drupal Core versions from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, and from 11.0.0 before 11.0.8.
What impact does CVE-2024-12393 have on my Drupal site?
The impact of CVE-2024-12393 can lead to the leakage of sensitive information if status messages are not properly sanitized.
Is it necessary to conduct a security audit after fixing CVE-2024-12393?
Yes, conducting a security audit after fixing CVE-2024-12393 is recommended to ensure that no other vulnerabilities exist.