Medium severity5.4NVD Advisory· Published Jan 9, 2025· Updated Jun 17, 2026
CVE-2024-13237
CVE-2024-13237
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity (fieldable files) allows Cross-Site Scripting (XSS).This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.38.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:file_entity_project:file_entity:*:*:*:*:*:drupal:*:*Range: >=7.x-2.0,<7.x-2.38
- Range: <7.x-2.38
- Range: 7.x-*
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2024-001nvdVendor Advisory
News mentions
0No linked articles in our index yet.