Описание
Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.
Note: This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.
The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of drupal/unified_twig_ext
EPSS
Процентиль: 11%
0.00039
Низкий
4.6 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
github
4 месяца назад
drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
EPSS
Процентиль: 11%
0.00039
Низкий
4.6 Medium
CVSS3
Дефекты
CWE-79