Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that can lead to Cross‑Site Scripting (XSS). An attacker can inject arbitrary JavaScript into pages rendered by Drupal core, which could be used to steal session cookies, perform credential hijacking, or carry out phishing attacks against site users. The flaw arises from insufficient sanitization of user input prior to outputting it to web pages.
Affected Systems
Drupal core is affected. Versions vulnerable include all releases from 0.0.0 through 11.2.*, the 11.3 series from 11.3.0 to 11.3.14, and the 11.4 series from 11.4.0 to 11.4.4. Sites running any of these versions are at risk.
Risk and Exploitability
The CVSS score is not provided, but the vulnerability is rated as moderately critical by Drupal. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly reported exploitation yet. The attack vector is likely client‑side via crafted input that gets rendered on a page, so any user with a capability to submit data that is not properly sanitized is capable of triggering the flaw. Exploitation would not require privileged access, making the threat relevant to users or administrators with content editing permissions.
OpenCVE Enrichment