Medium severity5.4NVD Advisory· Published Jan 9, 2025· Updated Jun 17, 2026
CVE-2024-13273
CVE-2024-13273
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:getopensocial:open_social:*:*:*:*:*:drupal:*:*+ 10 more
- cpe:2.3:a:getopensocial:open_social:*:*:*:*:*:drupal:*:*range: <12.3.8
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha1:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha10:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha2:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha3:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha4:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha5:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha6:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha7:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha8:*:*:*:drupal:*:*
- cpe:2.3:a:getopensocial:open_social:13.0.0:alpha9:*:*:*:drupal:*:*
0.0.0+ 1 more
- (no CPE)range: 0.0.0
- (no CPE)range: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2024-037nvdThird Party Advisory
News mentions
0No linked articles in our index yet.