CVE-2024-13247: Coffee - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-011
Published Jan 9, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.
Affected Software
2 affected components
Drupal Coffee<1.4.0
Coffee Project Coffee Drupal>=7.x-1.0<8.x-1.4
Event History
Jan 9, 2025
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13247?
CVE-2024-13247 is classified as a high severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2024-13247?
To fix CVE-2024-13247, upgrade Drupal Coffee to version 1.4.0 or later.
3
What software is affected by CVE-2024-13247?
CVE-2024-13247 affects Drupal Coffee versions from 0.0.0 up to, but not including, 1.4.0.
4
What type of vulnerability is CVE-2024-13247?
CVE-2024-13247 is a Cross-Site Scripting (XSS) vulnerability caused by improper input neutralization during web page generation.
5
Who is the vendor for CVE-2024-13247?
The vendor for CVE-2024-13247 is Drupal, specifically for the Coffee module.