Low severity3.8NVD Advisory· Published Jan 9, 2025· Updated Jun 17, 2026
CVE-2024-13308
CVE-2024-13308
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
51.0.0+ 1 more
- (no CPE)range: 1.0.0
- (no CPE)range: from 1.0.0 before 2.0.2
cpe:2.3:a:browser_back_button_project:browser_back_button:*:*:*:*:*:drupal:*:*+ 2 more
- cpe:2.3:a:browser_back_button_project:browser_back_button:*:*:*:*:*:drupal:*:*range: >=2.0.0,<2.0.2
- cpe:2.3:a:browser_back_button_project:browser_back_button:8.x-1.0:*:*:*:*:drupal:*:*
- cpe:2.3:a:browser_back_button_project:browser_back_button:8.x-1.1:*:*:*:*:drupal:*:*
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2024-072nvdThird Party Advisory
News mentions
0No linked articles in our index yet.