{"id":"DRUPAL-CONTRIB-2025-007","details":"This module enables you to render error pages using the Ignition package.\n\nThe module disables certain Drupal core code and does not perform sufficient filtering, allowing HTML to be injected in certain situations leading to a Cross Site Scripting (XSS) vulnerability.\n\nThis vulnerability is mitigated by the fact that this module is for development purposes and is not intended to be installed on production environments.","aliases":["CVE-2025-31679","GHSA-rhxm-r44m-4325"],"modified":"2026-09-10T03:45:41.418454859Z","published":"2025-01-22T17:01:38Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-007"}],"affected":[{"package":{"name":"drupal/ignition","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/ignition?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.4"}],"database_specific":{"constraint":"\u003c1.0.4"}}],"database_specific":{"affected_versions":"\u003c1.0.4","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ignition/DRUPAL-CONTRIB-2025-007.json"}}],"schema_version":"1.9.0","credits":[{"name":"Dieter Holvoet","contact":["https://www.drupal.org/user/3567222"]}]}