CVE-2024-13237: File Entity (fieldable files) - Moderately critical - Cross Site Scripting, Access bypass - SA-CONTRIB-2024-001
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity (fieldable files) allows Cross-Site Scripting (XSS).This issue affects File Entity (fieldable files): from 7.X- before 7.X-2.38.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13237?
CVE-2024-13237 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-13237?
To fix CVE-2024-13237, upgrade your Drupal File Entity module to version 7.X-2.38 or later.
Which versions of Drupal are affected by CVE-2024-13237?
CVE-2024-13237 affects Drupal File Entity versions prior to 7.X-2.38.
What type of vulnerability is CVE-2024-13237?
CVE-2024-13237 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-Site Scripting (XSS).
Who should be concerned about CVE-2024-13237?
Web administrators and developers using affected versions of Drupal File Entity should be concerned about CVE-2024-13237.