SA-CORE-2025-004: XSS
Drupal core Link field attributes are not sufficiently sanitized, which can lead to a Cross Site Scripting vulnerability (XSS). This vulnerability is mitigated by that fact that an attacker would need to have the ability to add specific attributes to a Link field, which typically requires edit access via core web services, or a contrib or custom module. Sites with the Link module disabled or that do not use any link fields are not affected.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of SA-CORE-2025-004?
The severity of SA-CORE-2025-004 is classified as 'Moderately Critical' due to its potential to allow Cross Site Scripting (XSS) attacks.
How do I fix SA-CORE-2025-004?
To fix SA-CORE-2025-004, update your Drupal installation to the latest versions that are not affected, specifically versions 10.5 or higher, and 11.2 or higher.
What software versions are affected by SA-CORE-2025-004?
SA-CORE-2025-004 affects Drupal versions prior to 10.5 and 11.2, specifically versions up to 10.4 and 11.1.
What is the nature of the vulnerability in SA-CORE-2025-004?
SA-CORE-2025-004 involves insufficient sanitization of Link field attributes, leading to a potential Cross Site Scripting vulnerability.
Who is at risk from SA-CORE-2025-004?
Users with edit access who can add specific attributes to Link fields are at risk from the vulnerability described in SA-CORE-2025-004.