Cross-Site Scripting Vulnerability in Drupal Core by Drupal
CVE-2025-3057

6.1MEDIUM

Key Information:

Vendor
Drupal
Vendor
CVE Published:
31 March 2025

Summary

The vulnerability in Drupal core stems from improper neutralization of user input during web page generation, leading to Cross-Site Scripting (XSS) attacks. This flaw can allow untrusted data to be executed as script in the context of the browser, potentially compromising user interactions and web application security. Users of affected versions should update to secure versions to mitigate this risk.

Affected Version(s)

Drupal core 8.0.0 < 10.3.13

Drupal core 10.4.0 < 10.4.3

Drupal core 11.0.0 < 11.0.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arne (arkepp)
bdanin
Douglas Groene (dgroene)
Dragos Dumitrescu (dragos-dumi)
Flo Kosiol (flokosiol)
Gerardo Cadau (juanramonperez)
Justin Christoffersen (larsdesigns)
nuwans
Sven Decabooter (svendecabooter)
Will Gunn (wgunn_e)
catch (catch)
Drew Webber (mcdruid)
.