Junglewise Threat Intelligence

CVE-2024-13273: DRUPAL-CONTRIB-2024-037 - Open Social is a Drupal distribution for online communities, which ships with an optional module called Social Embed. This module allows a

CVE-2024-13273 · Severity: info · Published 2024-09-04

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Social. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Open Social is a Drupal distribution for online communities, which ships with an optional module called Social Embed.

This module allows a website to display embedded content (such as photos or videos) when a user posts a link to that resource, without having to parse the resource directly.

Added URL's were not sufficiently validated which could lead to a DoS via Blind SSRF and/or Application Takeover via Stored XSS.

This vulnerability is mitigated by the fact that social\_embed submodule needs to be enabled.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/social

Related threats