Cross-Site Scripting Vulnerability in Drupal baguetteBox.Js
CVE-2025-3733

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
16 April 2025

Summary

An input validation flaw has been identified in the Drupal baguetteBox.Js library, allowing malicious actors to execute Cross-Site Scripting (XSS) attacks. This vulnerability affects multiple versions of the baguetteBox.Js library, presenting a significant risk to web applications that utilize this component, especially those using versions prior to 2.0.4 and between 3.0.0 and 3.0.1. Proper sanitization measures are essential to protect against potential exploitation.

References

Timeline

  • Vulnerability published

.