CVE-2025-3901: Bootstrap Site Alert - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-042
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3901?
CVE-2025-3901 has a severity rating that indicates a potential for data exposure or compromise due to Cross-Site Scripting (XSS).
How do I fix CVE-2025-3901?
To fix CVE-2025-3901, update your Drupal Bootstrap Site Alert module to version 1.13.0 or 3.0.4 or later.
What versions of Drupal Bootstrap Site Alert are affected by CVE-2025-3901?
CVE-2025-3901 affects Drupal Bootstrap Site Alert versions from 0.0.0 before 1.13.0 and from 3.0.0 before 3.0.4.
What is the impact of CVE-2025-3901?
The impact of CVE-2025-3901 is the possibility for attackers to execute arbitrary scripts in the context of a user's session, leading to unauthorized information disclosure.
Are there any workarounds for CVE-2025-3901?
There are no confirmed workarounds for CVE-2025-3901; upgrading is the recommended action to mitigate the vulnerability.