VYPR
Medium severity5.4NVD Advisory· Published Jan 9, 2025· Updated Jun 17, 2026

CVE-2024-13273

CVE-2024-13273

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • cpe:2.3:a:getopensocial:open_social:*:*:*:*:*:drupal:*:*+ 10 more
    • cpe:2.3:a:getopensocial:open_social:*:*:*:*:*:drupal:*:*range: <12.3.8
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha1:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha10:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha2:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha3:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha4:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha5:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha6:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha7:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha8:*:*:*:drupal:*:*
    • cpe:2.3:a:getopensocial:open_social:13.0.0:alpha9:*:*:*:drupal:*:*
  • Drupal/Open Socialcpe-rescue2 versions
    0.0.0+ 1 more
    • (no CPE)range: 0.0.0
    • (no CPE)range: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.