First published: Wed Apr 23 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Bootstrap Site Alert | >0.0.0<1.13.0>3.0.0<3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3901 has a severity rating that indicates a potential for data exposure or compromise due to Cross-Site Scripting (XSS).
To fix CVE-2025-3901, update your Drupal Bootstrap Site Alert module to version 1.13.0 or 3.0.4 or later.
CVE-2025-3901 affects Drupal Bootstrap Site Alert versions from 0.0.0 before 1.13.0 and from 3.0.0 before 3.0.4.
The impact of CVE-2025-3901 is the possibility for attackers to execute arbitrary scripts in the context of a user's session, leading to unauthorized information disclosure.
There are no confirmed workarounds for CVE-2025-3901; upgrading is the recommended action to mitigate the vulnerability.