{"id":"DRUPAL-CONTRIB-2024-037","details":"Open Social is a Drupal distribution for online communities, which ships with an optional module called Social Embed.\n\nThis module allows a website to display embedded content (such as photos or videos) when a user posts a link to that resource, without having to parse the resource directly.\n\nAdded URL's were not sufficiently validated which could lead to a DoS via Blind SSRF and/or Application Takeover via Stored XSS.\n\nThis vulnerability is mitigated by the fact that social\\_embed submodule needs to be enabled.","aliases":["CVE-2024-13273"],"modified":"2026-03-18T18:00:07.487495Z","published":"2024-09-04T16:15:41Z","withdrawn":"2026-03-18T18:00:07.487495Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2024-037"}],"affected":[{"package":{"name":"drupal/social","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/social"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.3.8"}],"database_specific":{"constraint":"\u003c12.3.8"}},{"type":"ECOSYSTEM","events":[{"introduced":"12.4.0"},{"fixed":"12.4.5"}],"database_specific":{"constraint":"\u003e=12.4.0 \u003c12.4.5"}}],"database_specific":{"affected_versions":"\u003c12.3.8 || \u003e=12.4.0 \u003c12.4.5","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/social/DRUPAL-CONTRIB-2024-037.json"}}],"schema_version":"1.7.3","credits":[{"name":"Thiago Régis","contact":["https://www.drupal.org/user/277221"]}]}