SA-CORE-2024-005: Critical severity Drupal Drupal vulnerability
Published Nov 20, 2024
·Updated
Drupal 7 core's Overlay module doesn't safely handle user input, leading to reflected cross-site scripting under certain circumstances. Only sites with the Overlay module enabled are affected by this vulnerability.
Credit
Cesar
Affected Software
1 affected componentFixes available
Drupal Drupal<7
7
Event History
Nov 20, 2024
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of SA-CORE-2024-005?
The severity of SA-CORE-2024-005 is critical with a score of 9.
2
How do I fix SA-CORE-2024-005?
To fix SA-CORE-2024-005, you should disable the Overlay module or upgrade your Drupal 7 installation to a patched version.
3
Who is affected by SA-CORE-2024-005?
Only sites with the Overlay module enabled are affected by SA-CORE-2024-005.
4
What type of vulnerability is SA-CORE-2024-005?
SA-CORE-2024-005 is a reflected cross-site scripting (XSS) vulnerability.
5
When was SA-CORE-2024-005 published?
SA-CORE-2024-005 was published on November 20, 2024.