First published: Wed Apr 02 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS. This issue affects Obfuscate: from 0.0.0 before 2.0.1.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Obfuscate | >0.0.0<2.0.1 | |
composer/drupal/obfuscate | <2.0.1 | 2.0.1 |
Drupal Obfuscate | <2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3130 has been classified as a high severity vulnerability due to its potential for storing Cross-site Scripting (XSS) attacks.
To fix CVE-2025-3130, you should upgrade Drupal Obfuscate to version 2.0.1 or later.
CVE-2025-3130 affects Drupal Obfuscate versions from 0.0.0 up to but not including 2.0.1.
CVE-2025-3130 is a Stored XSS vulnerability caused by improper neutralization of input during web page generation.
To determine if your website is vulnerable to CVE-2025-3130, check if it is using an affected version of Drupal Obfuscate prior to 2.0.1.