Cross-Site Scripting Vulnerability in Drupal OAuth & OpenID Connect SSO
CVE-2024-13301

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
9 January 2025

Summary

An input validation flaw in the Drupal OAuth & OpenID Connect Single Sign On – SSO component allows attackers to execute arbitrary JavaScript code in the context of the user’s session. This security issue can be exploited via specially crafted input, leading to potential data theft and session hijacking. It affects specific versions of the module, underscoring the need for immediate updates and adherence to best security practices.

References

Timeline

  • Vulnerability published

.