Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64mv-9655-37hx

Опубликовано: 10 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.9

Описание

drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS

Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.

Note: This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.

The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of drupal/unified_twig_ext, but is not published to the Composer PHP registry.

Пакеты

Наименование

drupal-pattern-lab/unified-twig-extensions

composer
Затронутые версииВерсия исправления

<= 0.1.0

Отсутствует

EPSS

Процентиль: 12%
0.00039
Низкий

1.9 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
nvd
4 месяца назад

Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab. The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of [drupal/unified_twig_ext](https://www.drupal.org/project/unified_twig_ext)

EPSS

Процентиль: 12%
0.00039
Низкий

1.9 Low

CVSS4

Дефекты

CWE-79