Cross-Site Scripting Vulnerability in Drupal OAuth & OpenID Connect SSO
CVE-2024-13301
Currently unrated
Summary
An input validation flaw in the Drupal OAuth & OpenID Connect Single Sign On – SSO component allows attackers to execute arbitrary JavaScript code in the context of the user’s session. This security issue can be exploited via specially crafted input, leading to potential data theft and session hijacking. It affects specific versions of the module, underscoring the need for immediate updates and adherence to best security practices.
References
Timeline
Vulnerability published