Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18295 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-073 |
|
Fri, 18 Jul 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1xinternet
1xinternet simple Klaro |
|
| CPEs | cpe:2.3:a:1xinternet:simple_klaro:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Klaro
Klaro simple Klaro |
1xinternet
1xinternet simple Klaro |
Tue, 15 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 06:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Klaro
Klaro simple Klaro |
|
| CPEs | cpe:2.3:a:klaro:simple_klaro:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Klaro
Klaro simple Klaro |
Sat, 14 Jun 2025 02:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 14 Jun 2025 00:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0. | |
| Title | Simple Klaro - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-073 | |
| Weaknesses | CWE-79 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-06-13T16:37:55.768Z
Reserved: 2025-05-28T14:59:40.500Z
Link: CVE-2025-48919
Updated: 2025-06-13T16:37:38.300Z
Status : Analyzed
Published: 2025-06-13T16:15:27.177
Modified: 2025-07-17T16:04:56.913
Link: CVE-2025-48919
No data.
OpenCVE Enrichment
No data.
EUVD