Cross-Site Scripting Vulnerability in Drupal Toc.Js
CVE-2025-48923
Currently unrated
What is CVE-2025-48923?
A Cross-Site Scripting (XSS) vulnerability exists in Drupal's Toc.Js, which could allow an attacker to inject malicious scripts through improperly sanitized user input during web page generation. This flaw can expose users to a range of attacks, including data theft and session hijacking, if not addressed appropriately.
Affected Version(s)
Toc.js 0.0.0 < 3.2.1