{ "canonical_id": "drupal--b57027329e", "system_id": "drupal", "display_name": "Drupal", "category": "cms", "advisory_mode": "core", "title": "Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005", "summary": "
Drupal 7 core's Overlay module doesn't safely handle user input, leading to reflected cross-site scripting under certain circumstances.
\nOnly sites with the Overlay module enabled are affected by this vulnerability.
Install the latest version:
\nDrupal 10 and Drupal 11 are not affected, as the Overlay module was removed from Drupal core in Drupal 8.