Junglewise Threat Intelligence

CVE-2024-13283: DRUPAL-CONTRIB-2024-047 - This module enables you to to easily create and manage faceted search interfaces. The module doesn't sufficiently filter for malicious scri

CVE-2024-13283 · Severity: info · Published 2024-10-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Facets. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module enables you to to easily create and manage faceted search interfaces.

The module doesn't sufficiently filter for malicious script leading to a reflected cross site scripting (XSS) vulnerability.

The vulnerability exists in the Facets Summary submodule. If you do not use that sub module your site is not vulnerable to this issue.

*Edited October 9, 2024: clarified that Facets Summary is where the vulnerability is located*

Affected products

  • packagist:https://packages.drupal.org/8 drupal/facets

Related threats